Courseiva

First Step: Isolate Affected Endpoints with Microsoft Defender for Endpoint

Your organization uses Microsoft Sentinel as its SIEM and Microsoft Defender XDR for endpoint detection. A critical incident has been generated: 'Possible ransomware activity detected on multiple endpoints.' The incident includes alerts from Microsoft Defender for Endpoint (MDE) about file encryption behaviors and from Microsoft Defender for Identity (MDI) about anomalous service account logins. You have been assigned the incident and need to contain the threat effectively. You have Microsoft Sentinel automation rules that can trigger playbooks, and you have Microsoft Defender XDR actions available. The environment includes 500 Windows 10 devices managed by Microsoft Intune, and 50 servers on-premises. Some servers are domain controllers. Which of the following is the BEST first course of action?

Quick Answer

The answer is to isolate the affected devices using Microsoft Defender for Endpoint device isolation. This is the correct first course of action because it immediately stops the ransomware from encrypting further files and communicating with command-and-control servers, while preserving forensic data for later analysis. In the context of the SC-200 exam, this question tests your ability to prioritize containment over investigation or credential management during an active ransomware incident—a common trap is choosing to disable accounts or run playbooks first, which wastes critical time. A key memory tip is “Isolate first, investigate second”: when you need to isolate multiple endpoints during a ransomware incident, always use MDE’s built-in isolation action before touching identity or automation, as it directly halts the encryption process and prevents lateral movement.

⚠ Common exam trap

SC-200 often tests the order of incident response phases — candidates pick forensic collection or account resets because they sound thorough, but containment (isolation) must come first to stop active encryption.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Isolate the affected devices using Microsoft Defender for Endpoint device isolation.

For active ransomware encrypting files across multiple endpoints, the priority is to stop the spread immediately. Microsoft Defender for Endpoint device isolation cuts network communication while preserving the Defender sensor channel for investigation, containing the threat before lateral movement or further encryption. Forensic collection and account remediation are important but secondary to stopping active encryption.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Disable all compromised service accounts in Microsoft Entra ID and reset their passwords.

    Why it's wrong here

    Disabling service accounts in Microsoft Entra ID addresses only cloud identities, leaving the on-premises domain controllers and the active file-encryption processes on endpoints untouched. It is tempting because MDI flagged anomalous service account logins, and would be correct once the endpoint threat is isolated and the scope of identity compromise is confirmed.

  • ✗

    Reset passwords for all domain administrator accounts and enforce MFA.

    Why it's wrong here

    Resetting domain administrator passwords and enforcing MFA does not stop the file-encryption processes already running on endpoints, nor isolate the affected devices. It is tempting because MDI reported anomalous service account logins, and would be correct for hardening privileged identity after the active ransomware execution is halted.

  • ✗

    Trigger a Microsoft Sentinel playbook to collect forensic evidence from affected endpoints before remediation.

    Why it's wrong here

    Collecting forensic evidence first leaves ransomware encrypting files across endpoints while the playbook runs, delaying containment. It is tempting because preserving artefacts supports later investigation, and would be correct after the threat is contained and the affected devices are isolated from the network.

  • ✓

    Isolate the affected devices using Microsoft Defender for Endpoint device isolation.

    Why this is correct

    Device isolation via Microsoft Defender for Endpoint immediately cuts network communication while preserving forensic evidence, halting ransomware spread across endpoints. It addresses the active encryption behaviour first, before investigating the MDI service account logins, containing the threat fastest.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SC-200

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Your organization uses Microsoft Sentinel and Microsoft Defender XDR. You receive an incident: 'Malicious PowerShell command executed on endpoint.' The incident shows that a PowerShell command was executed on a server that attempted to download a payload from a known malicious IP. The process was terminated by MDE, but the server may still be compromised. You need to respond to the incident. Which of the following actions should you take FIRST?

medium
  • A.Run a Microsoft Sentinel playbook to collect forensic data.
  • ✓ B.Isolate the server using Microsoft Defender for Endpoint.
  • C.Reset the local administrator password on the server.
  • D.Block the malicious IP address at the firewall.

Why B: The server executed a malicious PowerShell command that attempted to download a payload from a known malicious IP, and although MDE terminated the process, the host may still be compromised. The first priority in incident response is containment, and isolating the endpoint via Microsoft Defender for Endpoint immediately prevents further command-and-control, lateral movement, or additional payload downloads while investigation proceeds.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.