Courseiva

SC-200 Respond to security incidents Practice Question

Which THREE steps are part of the containment phase of incident response in a hybrid environment using Microsoft Defender XDR?

⚠ Common exam trap

The trap is mixing up incident response phases — candidates often select eradication or recovery actions (like removing malware or restoring backups) thinking they are containment.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Disable compromised user accounts in Microsoft Entra ID

Option C is correct because disabling compromised user accounts in Microsoft Entra ID is a classic containment action that stops an attacker from continuing to use stolen credentials for lateral movement or further access. Option D is correct because isolating affected devices via Microsoft Defender for Endpoint cuts off the endpoint's network communication while preserving it for investigation, which is a core containment step in a hybrid environment. Option E is correct because blocking malicious IP addresses at the firewall prevents ongoing command-and-control or exfiltration traffic to known-bad infrastructure, containing the spread of the incident. Options A and B are not containment: removing malware is part of eradication, and restoring data from backups belongs to the recovery phase, which occurs after the threat has been fully eliminated.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Remove malware from affected systems

    Why it's wrong here

    Removing malware is eradication, performed after containment has stopped the spread, not during containment itself. It is tempting because cleaning infected hosts feels urgent, but eradication would be correct once compromised systems are isolated and the immediate threat is halted.

  • ✗

    Restore data from backups

    Why it's wrong here

    Restoring data from backups belongs to the recovery phase, occurring after the threat is eradicated and systems are rebuilt. It is tempting because backups are essential to incident response, and restoration would be correct once containment and eradication are complete and normal operations resume.

  • ✓

    Disable compromised user accounts in Microsoft Entra ID

    Why this is correct

    Disabling compromised accounts in Microsoft Entra ID immediately revokes authentication, blocking the attacker from re-entering the environment via cloud or hybrid identity paths. This directly satisfies containment by stopping lateral movement and further compromise while investigation continues, rather than merely detecting or documenting the incident.

  • ✓

    Isolate affected devices using Microsoft Defender for Endpoint

    Why this is correct

    Isolating affected devices via Microsoft Defender for Endpoint severs network connectivity while preserving forensic evidence and allowing remediation, containing the threat without wiping the endpoint. This stops lateral spread during the containment phase of hybrid incident response.

  • ✓

    Block malicious IP addresses at the firewall

    Why this is correct

    Blocking malicious IP addresses at the perimeter firewall directly severs the attacker's command-and-control and lateral movement paths, satisfying the containment requirement to limit blast radius before eradication. In a hybrid environment, Microsoft Defender XDR surfaces the offending IPs as indicators, which you then enforce at the network edge to stop ongoing intrusion.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.