Courseiva

SC-200 Respond to security incidents Practice Question

Which THREE of the following are key steps when containing a ransomware incident in Microsoft Defender XDR? (Select THREE.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Block known malicious file hashes via Indicators of compromise

Blocking malicious file hashes via indicators of compromise (B), disabling compromised user accounts (C), and isolating compromised devices (E) are key steps in containing a ransomware incident. Restoring from backup (A) is part of recovery, and analyzing root cause (D) is part of investigation, both of which occur after containment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Restore encrypted files from backup

    Why it's wrong here

    Backup restoration is recovery, which follows containment and eradication. Containment isolates affected endpoints and accounts, blocks malicious indicators and severs lateral movement. Restoring files would be the correct step once the threat is fully evicted, during the recovery phase of the incident response lifecycle.

  • ✓

    Block known malicious file hashes via Indicators of compromise

    Why this is correct

    Blocking known malicious file hashes through indicators of compromise directly satisfies the containment requirement by preventing execution of identified ransomware binaries across endpoints. Custom file-hash indicators in Microsoft Defender XDR enforce immediate prevention, halting lateral spread while investigation continues, and this deterministic, signature-based control is a recognised containment step.

  • ✓

    Disable compromised user accounts in Microsoft Entra ID

    Why this is correct

    Disabling the compromised accounts in Microsoft Entra ID immediately revokes authentication and token issuance, cutting the attacker's access to email, files and cloud apps. This containment step stops lateral movement and further encryption while investigation continues.

  • ✗

    Analyze the root cause of the outbreak

    Why it's wrong here

    Root-cause analysis belongs to post-incident investigation, after containment and eradication are complete. Containment actions isolate compromised devices, disable breached accounts and block command-and-control traffic. Analysing the outbreak's origin would be appropriate during the lessons-learned review, not while the attacker still has active access.

  • ✓

    Isolate compromised devices using Microsoft Defender for Endpoint

    Why this is correct

    Isolating compromised devices via Microsoft Defender for Endpoint severs the attacker's lateral movement and command-and-control channels, directly satisfying the containment requirement. Device isolation preserves forensic evidence for investigation while blocking further encryption or exfiltration, making it a foundational step in the Microsoft Defender XDR ransomware playbook.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.