SC-200 Respond to security incidents Practice Question
Which TWO actions should a SOC analyst take immediately after confirming a ransomware incident in Microsoft Defender XDR?
⚠ Common exam trap
SC-200 often tests the confusion between containment actions and recovery or forensic actions, tempting candidates to choose backup restoration or memory collection as 'immediate' steps when they are actually later-phase activities.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Isolate affected devices from the network.
Option A is correct because isolating affected devices in Microsoft Defender XDR (via the device isolation action) immediately stops lateral movement, command-and-control communication, and further encryption by cutting the host off from the network while preserving the ability to investigate remotely. Option D is correct because ransomware actors commonly obtain and reuse compromised credentials, so resetting passwords for affected accounts and enforcing MFA revokes the attacker's access and prevents re-entry or persistence through valid accounts. Option B is not an immediate containment action; restoring from backups should occur only after the threat is contained and the environment is verified clean, otherwise restored data can be re-encrypted. Option C is too broad and destructive — disabling all mailboxes organization-wide is not a proportionate or standard ransomware response and would disrupt business without addressing the root compromise. Option E, collecting a full memory dump, is a forensic step that may be valuable later but is not one of the two immediate containment and credential-remediation actions required upon confirmation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Isolate affected devices from the network.
Why this is correct
Isolating affected devices at the switch or via VLAN segmentation immediately stops the ransomware's lateral movement over SMB, RDP, or WinRM, while keeping the device powered on so volatile data remains intact for later forensic acquisition. This containment measure is the top priority because a single connected endpoint can encrypt an entire network in minutes, including backups that are mounted as network drives.
- ✗
Begin restoring data from backups.
Why it's wrong here
Restoring data before the active intrusion is fully contained is dangerous because a persistent attacker or a lingering ransomware process will simply re-encrypt the restored files, and the restore may put you back into a compromised state if the backups themselves are tainted. Incident response protocols require completing eradication—identifying the initial access vector and removing the adversary—before any recovery step, otherwise you risk reinfection and hours of wasted effort.
- ✗
Disable all mailboxes in the organization.
Why it's wrong here
Disabling every mailbox in the organization is an indiscriminate action that disrupts the entire business without targeting the actual compromised accounts, and it invites user panic and a flood of help-desk tickets. The correct scoped action is to use Microsoft 365 Defender and Unified Audit Log to identify accounts with anomalous sign-ins, unusual forwarding rules, or actor-assigned permissions, then disable only those specific identities and enforce conditional access policies.
- ✓
Reset passwords for compromised accounts and enforce MFA.
Why this is correct
Resetting credentials for confirmed compromised accounts and forcing MFA registration blocks the attacker's existing authentication tokens and current logon sessions, while preventing them from reusing the stolen password in a different session. This containment step is essential but must be combined with a review of OAuth grants and MFA device registration because attackers may have registered their own authenticator or created an app-role access policy.
- ✗
Collect a full memory dump from each affected device.
Why it's wrong here
Collecting a full memory dump is a forensic procedure that belongs after the endpoint is isolated, not during, because an uncontained device might be re-encrypting files while you are copying its RAM, and the memory dump itself can be incomplete or corrupted if the encryption process is competing for CPU and I/O. Additionally, the 'triage first' principle means you should analyze for active IOCs using fast methods like EDR telemetry or YARA scans before resorting to heavy memory acquisition.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SC-200
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which TWO actions should an analyst take when a confirmed ransomware incident is detected on multiple endpoints? (Choose TWO.)
medium- A.Run a full antivirus scan on all endpoints.
- ✓ B.Isolate affected endpoints using Microsoft Defender for Endpoint.
- ✓ C.Block known malicious IP addresses and domains in the firewall.
- D.Disconnect network cables but leave endpoints powered on.
- E.Shut down all affected endpoints to prevent data loss.
Why B: Microsoft Defender for Endpoint's device isolation feature immediately severs all network communication (both inbound and outbound) from the affected endpoint while keeping the device powered on for forensic analysis. This containment action prevents lateral movement and further encryption of data across the network, which is critical during a ransomware incident.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.