SC-200 Respond to security incidents Practice Question
Which THREE of the following are key steps when containing a ransomware incident in Microsoft Defender XDR? (Select THREE.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Block known malicious file hashes via Indicators of compromise
Blocking malicious file hashes via indicators of compromise (B), disabling compromised user accounts (C), and isolating compromised devices (E) are key steps in containing a ransomware incident. Restoring from backup (A) is part of recovery, and analyzing root cause (D) is part of investigation, both of which occur after containment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Restore encrypted files from backup
Why it's wrong here
Backup restoration is recovery, which follows containment and eradication. Containment isolates affected endpoints and accounts, blocks malicious indicators and severs lateral movement. Restoring files would be the correct step once the threat is fully evicted, during the recovery phase of the incident response lifecycle.
- ✓
Block known malicious file hashes via Indicators of compromise
Why this is correct
Blocking known malicious file hashes through indicators of compromise directly satisfies the containment requirement by preventing execution of identified ransomware binaries across endpoints. Custom file-hash indicators in Microsoft Defender XDR enforce immediate prevention, halting lateral spread while investigation continues, and this deterministic, signature-based control is a recognised containment step.
- ✓
Disable compromised user accounts in Microsoft Entra ID
Why this is correct
Disabling the compromised accounts in Microsoft Entra ID immediately revokes authentication and token issuance, cutting the attacker's access to email, files and cloud apps. This containment step stops lateral movement and further encryption while investigation continues.
- ✗
Analyze the root cause of the outbreak
Why it's wrong here
Root-cause analysis belongs to post-incident investigation, after containment and eradication are complete. Containment actions isolate compromised devices, disable breached accounts and block command-and-control traffic. Analysing the outbreak's origin would be appropriate during the lessons-learned review, not while the attacker still has active access.
- ✓
Isolate compromised devices using Microsoft Defender for Endpoint
Why this is correct
Isolating compromised devices via Microsoft Defender for Endpoint severs the attacker's lateral movement and command-and-control channels, directly satisfying the containment requirement. Device isolation preserves forensic evidence for investigation while blocking further encryption or exfiltration, making it a foundational step in the Microsoft Defender XDR ransomware playbook.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.