Courseiva

SC-200 Respond to security incidents Practice Question

Which TWO actions are appropriate when responding to a confirmed data exfiltration incident via email?

⚠ Common exam trap

Many candidates confuse immediate containment (disabling the account) with proper forensic preservation, forgetting that disabling the account can destroy volatile evidence and alert the adversary, while blocking the recipient domain is a more precise containment action.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Block the recipient domain on the email gateway

Blocking the recipient domain on the email gateway (A) is appropriate because it immediately prevents further data exfiltration to that external domain by rejecting all outbound emails to that domain at the transport layer. Placing a legal hold on the user's mailbox (B) preserves all mailbox content, including deleted items, as an immutable copy for forensic investigation and potential legal proceedings, ensuring evidence is not lost during the incident response.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Block the recipient domain on the email gateway

    Why this is correct

    Blocking the recipient domain on the email gateway is an appropriate containment action because it immediately halts the active data exfiltration channel by rejecting any further outbound messages destined for that domain. This measure is applied at the transport layer, so it stops the bleeding without deleting any previously sent evidence, and it preserves the ability to later analyze the full extent of the breach while preventing additional data loss.

  • ✓

    Place a legal hold on the user's mailbox

    Why this is correct

    Placing a legal hold on the user's mailbox is appropriate because it ensures all mailbox content, including deleted items, drafts, and metadata, is preserved in place and immutable for eDiscovery purposes. This action protects the integrity of the evidence, maintains a proper chain of custody, and prevents accidental or malicious destruction during the investigation, which is critical for both internal forensics and potential legal proceedings.

  • ✗

    Disable the user's account immediately

    Why it's wrong here

    Disabling the user's account immediately is not appropriate because the account may be legitimate and the exfiltration might be the result of a compromised mailbox or a misconfigured rule, not a malicious insider. Locking the account prematurely can alert the attacker, interrupt business continuity, and destroy the ability to observe the attacker's live activity, which could be crucial for identifying the full scope of the incident and the attack vector.

  • ✗

    Delete all sent items from the user's mailbox

    Why it's wrong here

    Deleting all sent items from the user's mailbox is a destructive action that removes the primary forensic artifacts needed to understand the exfiltration, including recipient addresses, timestamps, subject lines, and the exact content sent. Such deletion constitutes spoliation of evidence, breaks the chain of custody, and can severely hamper legal or disciplinary actions, making it the opposite of a proper incident response step.

  • ✗

    Run a full antivirus scan on the user's device

    Why it's wrong here

    Running a full antivirus scan on the user's device is not directly relevant to email data exfiltration, as the exfiltration occurred through the email channel and the evidence resides in the mailbox and email gateway logs. While malware could be a vector, the immediate priority is to stop the data flow and preserve forensic evidence; a scan might also alter file access times or make system changes that could interfere with later forensic analysis.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.