SC-200 Respond to security incidents Practice Question
Which TWO actions are appropriate when responding to a confirmed malware outbreak on multiple workstations identified by Microsoft Defender for Endpoint?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Collect investigation packages from the affected devices for analysis.
Collecting investigation packages and isolating affected devices are appropriate response actions. Running a full scan is reactive and not immediate. Resetting passwords may be needed later but not first. Blocking indicators is proactive but doesn't contain already infected devices.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Collect investigation packages from the affected devices for analysis.
Why this is correct
Collecting investigation packages from affected devices is appropriate because it captures volatile forensic artifacts—such as running processes, active network connections, registry keys, and loaded drivers—in their current live state. This package enables analysts to identify Indicators of Compromise (IOCs), the initial access vector, and the full lateral movement scope without altering or destroying evidence. It is a non-disruptive collection action that complements containment, ensuring the investigation has the data needed to understand the outbreak before any cleanup begins.
- ✗
Add the malware hash to the custom threat indicator list.
Why it's wrong here
Adding the malware hash to a custom threat indicator list is a preventive control: it configures Microsoft Defender for Endpoint to block or alert on that specific file hash in the future, but it has no effect on devices where the malware is already present and executing. This action does not terminate the ongoing network communication or stop the malware from spreading across the enterprise, because the hash block only applies to new detections. As such, it is a follow-up hardening step, not an appropriate immediate containment action during an active outbreak.
- ✗
Run a full antivirus scan on all workstations.
Why it's wrong here
Running a full antivirus scan on all workstations is a remediation step, not a containment step, and in an active outbreak it may actually trigger the malware to react to scan activity—such as encrypting files or propagating further—before the scan completes. A scan only addresses file-based threats; it does not block the malware's command-and-control (C2) channel or any remote/network-based lateral movement. Proper incident response prioritizes isolating affected hosts and collecting evidence, then running scans only after containment to clean the environment and verify eradication.
- ✗
Reset passwords of all users who logged into the affected devices.
Why it's wrong here
Resetting passwords for all users who logged into affected devices is an important post-containment mitigation, but doing so during the initial response can prematurely alter the investigation landscape by locking out active sessions and disrupting the ability to observe adversary behavior. It can also mask the true scope of credential theft because the security operations team may lose visibility into the attacker's actions before they have fully mapped the lateral movement. The correct sequence is to isolate devices, collect investigation packages, and then reset credentials after the scope of compromised accounts is confirmed.
- ✓
Isolate the affected devices from the network using Microsoft Defender for Endpoint.
Why this is correct
Isolating the affected devices from the network using Microsoft Defender for Endpoint is a primary containment action because the isolation action severs all inbound and outbound network traffic at the sensor level—while still allowing the MDE telemetry channel to send data to the cloud. This immediately breaks the malware's command-and-control (C2) communication and prevents it from spreading laterally to other hosts, without powering off the device or losing forensic state. It is an appropriate, immediate response that can be executed remotely and safely preserves the device for further investigation.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.