SC-200 Respond to security incidents Practice Question
Which TWO actions are appropriate when handling a confirmed ransomware incident in Microsoft 365?
⚠ Common exam trap
SC-200 often tests the misconception that immediate restoration or antivirus scanning is the first response to ransomware, when in fact containment and identity remediation are the priority.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Isolate affected devices from the network.
Option D is correct because isolating affected devices from the network is a standard containment step that prevents the ransomware from spreading laterally to other endpoints and limits further encryption or exfiltration within the Microsoft 365 environment. Option E is correct because changing passwords for all potentially compromised accounts revokes the attackers' access, invalidates stolen credentials, and is essential when identity compromise (e.g., via phishing or token theft) is a common ransomware entry vector in Microsoft 365. Option A is not appropriate as a primary incident response action because a full antivirus scan is a remediation/detection step that does not contain an active ransomware incident and may be ineffective against fileless or cloud-based attacks. Option B is wrong because restoring from backup immediately without investigation can reintroduce the threat or restore already-compromised data, and the root cause must be identified first. Option C is wrong because paying the ransom is discouraged by Microsoft and law enforcement, does not guarantee data recovery, and may fund further criminal activity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Run a full antivirus scan on all devices.
Why it's wrong here
Running a full antivirus scan across all devices is an inadequate first response because it consumes time and system resources while the ransomware continues to encrypt files. More importantly, modern ransomware variants often disable or evade endpoint protection, so a scan may return false negatives and provide a misleading sense of security. The immediate priority must be containment through isolation and network segmentation to halt the spread, followed by identifying the initial access vector and rotating credentials.
- ✗
Restore encrypted files from backup immediately without investigation.
Why it's wrong here
Restoring encrypted files from backup immediately, without first investigating the intrusion, risks reintroducing the attacker's foothold or restoring a compromised backup along with the ransomworm payload. You must first determine the initial access method, the ransomware variant, and the scope of the infection to ensure the chosen backup set is clean and the environment is hardened before recovery. Premature restoration can also destroy volatile forensic evidence needed for attribution and legal proceedings.
- ✗
Pay the ransom to regain access.
Why it's wrong here
Paying the ransom is not a defensible containment or recovery action because there is no technical guarantee the adversary will provide a functional decryption key, and many victims who pay never regain full access. Furthermore, the payment directly funds criminal infrastructure, encourages repeat targeting, and in some cases violates sanctions or regulatory requirements. Modern ransomware operations also double-extort victims, so paying does not prevent the attacker from leaking exfiltrated data after the fact.
- ✓
Isolate affected devices from the network.
Why this is correct
Isolating affected devices from the network is the correct containment measure because it immediately severs the ransomware's ability to propagate laterally via SMB, RDP, or other network protocols. This should be performed at the endpoint level (disconnecting the NIC or blocking in the switch/firewall) and ideally include domain controllers and backup servers to prevent mass encryption and credential theft. The goal is to preserve evidence and stop the incident from becoming a full-domain compromise while allowing responders to analyze the threat safely.
- ✓
Change passwords for all potentially compromised accounts.
Why this is correct
Changing passwords for all potentially compromised accounts is critical after containment because ransomware actors often harvest credentials — including local administrator, domain admin, and service account hashes — to move laterally and maintain persistence. Rotating passwords invalidates those stolen credentials, especially if you reset Kerberos tickets and revoke tokens, and should be performed for every account that touched the affected endpoints. Prioritize privileged accounts first, and implement conditional access or MFA enforcement to further block unauthorized authentication attempts.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.