Courseiva

SC-200 Respond to security incidents Practice Question

Exhibit

Refer to the exhibit.

PowerShell Output:
```
PS C:\> Get-MpThreat

ThreatID          : 2147685180
Action            : 6
Category          : 22
DidThreatExecute  : False
IsActive          : False
InitialDetectionTime : 3/15/2025 10:30:00 AM
Resources         : {file:_C:\Users\Public\malware.exe}
```

Exhibit: Output from Get-MpThreat cmdlet on a Windows 10 device.

Refer to the exhibit. An analyst runs Get-MpThreat on a device. Based on the output, what is the status of the threat?

⚠ Common exam trap

Many exam-takers confuse 'Blocked' with 'Quarantined' or assume any threat listed must have executed, but the 'ExecutionStatus' field explicitly clarifies whether the threat ran or was stopped pre-execution.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The threat was blocked and did not execute.

The output of Get-MpThreat shows the threat's state as 'Blocked' and its execution status as 'Not Executed'. This indicates that Microsoft Defender Antivirus successfully prevented the threat from running on the device. Therefore, the threat was blocked and did not execute, making D the correct answer.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The threat executed and is now inactive.

    Why it's wrong here

    The Get-MpThreat output explicitly shows DidThreatExecute as False, which means the threat did not execute its code on the device. Although IsActive is also False, indicating the threat is not currently running, the claim that it 'executed' is directly contradicted by the DidThreatExecute field. A threat that did not execute cannot be described as having run and then become inactive.

  • ✗

    The threat was quarantined and is still active.

    Why it's wrong here

    IsActive is False, meaning the threat is not currently active on the device, so saying it 'is still active' is factually wrong. Additionally, the output does not indicate a quarantine state; quarantine is a specific remediation action and does not align with the fields shown. The presence of DidThreatExecute=False and IsActive=False suggests the threat was blocked before execution, not quarantined while still active.

  • ✗

    The threat is currently active on the device.

    Why it's wrong here

    The IsActive field in the Get-MpThreat output is False, which directly contradicts the statement that the threat is 'currently active.' IsActive is the primary indicator of whether a detected threat is still running or present as an active process on the endpoint. Since IsActive is False, the threat is not active on the device, regardless of other fields.

  • ✓

    The threat was blocked and did not execute.

    Why this is correct

    This is the correct conclusion because the Get-MpThreat output shows both DidThreatExecute is False and IsActive is False. DidThreatExecute=False confirms that the threat did not run, while IsActive=False confirms it is not currently present or running, which aligns with a blocked state. In Microsoft Defender, a threat that was blocked before execution typically has these exact field values, indicating the attack was prevented.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.