Courseiva

SC-200 Respond to security incidents Practice Question

Which THREE actions are part of the containment phase in the Microsoft Incident Response process?

⚠ Common exam trap

The SC-200 exam often tests the distinction between containment and investigation phases, where candidates mistakenly choose forensic data collection (Option E) as containment, but in the IR process, containment must happen first to stop the bleeding before any evidence gathering that could alter system state.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Block known malicious IP addresses at the firewall.

Blocking known malicious IP addresses at the firewall is a containment action because it immediately stops inbound or outbound communication with threat actors, preventing further data exfiltration or command-and-control traffic. In the Microsoft Incident Response (IR) process, containment focuses on limiting the blast radius and stopping the spread of an attack, and firewall rules are a primary technical control for achieving this at the network perimeter.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Notify senior management of the incident.

    Why it's wrong here

    Notification is a communication and escalation activity that occurs throughout the incident response lifecycle, but it is not a containment action. Containment is specifically about taking technical or operational measures to stop the adversary from continuing their malicious activities, such as blocking, isolating, or disabling access. Informing senior management keeps stakeholders aware but does not alter the attacker's ability to move laterally, persist, or exfiltrate data.

  • ✓

    Block known malicious IP addresses at the firewall.

    Why this is correct

    Blocking known malicious IP addresses at the firewall is a direct and immediate containment action that severs the network communication path between the compromised environment and the attacker's command-and-control (C2) infrastructure. By applying egress and ingress rules to deny traffic to these IPs, you cut off remote commands, data exfiltration, and potential malware downloads, thereby limiting the adversary's operational control without disrupting normal business traffic.

  • ✓

    Disable compromised user accounts.

    Why this is correct

    Disabling compromised user accounts is an effective containment measure that immediately revokes the legitimate authentication credentials the attacker has been using. This action prevents the adversary from authenticating to email, VPN, domain resources, or any other service, effectively evicting them from their current session and stopping further unauthorized actions, such as privilege escalation or accessing sensitive data, under that identity.

  • ✓

    Isolate affected systems from the network.

    Why this is correct

    Isolating affected systems from the network is a classic containment step that physically or logically removes a compromised host from the rest of the environment, for example by disabling its network interface, applying a VLAN ACL, or using an EDR containment feature. This halts lateral movement, prevents the spread of malware, and stops outbound malicious traffic, while still preserving the system state for later forensic analysis without letting the attacker continue to operate.

  • ✗

    Collect forensic data from affected systems.

    Why it's wrong here

    Collecting forensic data is an investigative and evidence-preservation activity, not a containment action, because taking memory images, copying disk volumes, or capturing logs does not stop an active threat. In fact, focusing on collection before containment can allow the attacker to continue moving laterally or exfiltrating data while you are gathering artifacts. Containment should be performed first to halt the attack; forensic collection then occurs in a controlled, post-containment state to preserve evidence accurately.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.