SC-200 Respond to security incidents Practice Question
Which TWO actions are appropriate when responding to a confirmed data exfiltration incident via email?
⚠ Common exam trap
Many candidates confuse immediate containment (disabling the account) with proper forensic preservation, forgetting that disabling the account can destroy volatile evidence and alert the adversary, while blocking the recipient domain is a more precise containment action.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Block the recipient domain on the email gateway
Blocking the recipient domain on the email gateway (A) is appropriate because it immediately prevents further data exfiltration to that external domain by rejecting all outbound emails to that domain at the transport layer. Placing a legal hold on the user's mailbox (B) preserves all mailbox content, including deleted items, as an immutable copy for forensic investigation and potential legal proceedings, ensuring evidence is not lost during the incident response.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Block the recipient domain on the email gateway
Why this is correct
Blocking the recipient domain on the email gateway is an appropriate containment action because it immediately halts the active data exfiltration channel by rejecting any further outbound messages destined for that domain. This measure is applied at the transport layer, so it stops the bleeding without deleting any previously sent evidence, and it preserves the ability to later analyze the full extent of the breach while preventing additional data loss.
- ✓
Place a legal hold on the user's mailbox
Why this is correct
Placing a legal hold on the user's mailbox is appropriate because it ensures all mailbox content, including deleted items, drafts, and metadata, is preserved in place and immutable for eDiscovery purposes. This action protects the integrity of the evidence, maintains a proper chain of custody, and prevents accidental or malicious destruction during the investigation, which is critical for both internal forensics and potential legal proceedings.
- ✗
Disable the user's account immediately
Why it's wrong here
Disabling the user's account immediately is not appropriate because the account may be legitimate and the exfiltration might be the result of a compromised mailbox or a misconfigured rule, not a malicious insider. Locking the account prematurely can alert the attacker, interrupt business continuity, and destroy the ability to observe the attacker's live activity, which could be crucial for identifying the full scope of the incident and the attack vector.
- ✗
Delete all sent items from the user's mailbox
Why it's wrong here
Deleting all sent items from the user's mailbox is a destructive action that removes the primary forensic artifacts needed to understand the exfiltration, including recipient addresses, timestamps, subject lines, and the exact content sent. Such deletion constitutes spoliation of evidence, breaks the chain of custody, and can severely hamper legal or disciplinary actions, making it the opposite of a proper incident response step.
- ✗
Run a full antivirus scan on the user's device
Why it's wrong here
Running a full antivirus scan on the user's device is not directly relevant to email data exfiltration, as the exfiltration occurred through the email channel and the evidence resides in the mailbox and email gateway logs. While malware could be a vector, the immediate priority is to stop the data flow and preserve forensic evidence; a scan might also alter file access times or make system changes that could interfere with later forensic analysis.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.