SC-200 Respond to security incidents Practice Question
Which THREE actions are part of the containment phase in the Microsoft Incident Response process?
⚠ Common exam trap
The SC-200 exam often tests the distinction between containment and investigation phases, where candidates mistakenly choose forensic data collection (Option E) as containment, but in the IR process, containment must happen first to stop the bleeding before any evidence gathering that could alter system state.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Block known malicious IP addresses at the firewall.
Blocking known malicious IP addresses at the firewall is a containment action because it immediately stops inbound or outbound communication with threat actors, preventing further data exfiltration or command-and-control traffic. In the Microsoft Incident Response (IR) process, containment focuses on limiting the blast radius and stopping the spread of an attack, and firewall rules are a primary technical control for achieving this at the network perimeter.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Notify senior management of the incident.
Why it's wrong here
Notification is a communication and escalation activity that occurs throughout the incident response lifecycle, but it is not a containment action. Containment is specifically about taking technical or operational measures to stop the adversary from continuing their malicious activities, such as blocking, isolating, or disabling access. Informing senior management keeps stakeholders aware but does not alter the attacker's ability to move laterally, persist, or exfiltrate data.
- ✓
Block known malicious IP addresses at the firewall.
Why this is correct
Blocking known malicious IP addresses at the firewall is a direct and immediate containment action that severs the network communication path between the compromised environment and the attacker's command-and-control (C2) infrastructure. By applying egress and ingress rules to deny traffic to these IPs, you cut off remote commands, data exfiltration, and potential malware downloads, thereby limiting the adversary's operational control without disrupting normal business traffic.
- ✓
Disable compromised user accounts.
Why this is correct
Disabling compromised user accounts is an effective containment measure that immediately revokes the legitimate authentication credentials the attacker has been using. This action prevents the adversary from authenticating to email, VPN, domain resources, or any other service, effectively evicting them from their current session and stopping further unauthorized actions, such as privilege escalation or accessing sensitive data, under that identity.
- ✓
Isolate affected systems from the network.
Why this is correct
Isolating affected systems from the network is a classic containment step that physically or logically removes a compromised host from the rest of the environment, for example by disabling its network interface, applying a VLAN ACL, or using an EDR containment feature. This halts lateral movement, prevents the spread of malware, and stops outbound malicious traffic, while still preserving the system state for later forensic analysis without letting the attacker continue to operate.
- ✗
Collect forensic data from affected systems.
Why it's wrong here
Collecting forensic data is an investigative and evidence-preservation activity, not a containment action, because taking memory images, copying disk volumes, or capturing logs does not stop an active threat. In fact, focusing on collection before containment can allow the attacker to continue moving laterally or exfiltrating data while you are gathering artifacts. Containment should be performed first to halt the attack; forensic collection then occurs in a controlled, post-containment state to preserve evidence accurately.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.