Courseiva

SC-200 Respond to security incidents Practice Question

Which TWO actions should you perform to contain a ransomware incident in Microsoft Defender for Endpoint?

⚠ Common exam trap

Test-takers frequently confuse containment actions (like isolation and killing processes) with post-incident steps (like password resets, scanning, or sample collection), leading them to select options that are reactive rather than immediately preventive.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Isolate the device from the network.

Isolating the device from the network (Option B) is a critical containment step in a ransomware incident because it immediately stops the ransomware from communicating with its command-and-control (C2) server and prevents lateral movement to other devices. In Microsoft Defender for Endpoint, device isolation can be initiated from the Security Center, which applies a network-level block that only allows communication with the Defender for Endpoint service, effectively quarantining the device while preserving forensic data.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Reset the local administrator password.

    Why it's wrong here

    Resetting the local administrator password does not contain ransomware because the malicious code is already executing in the context of the compromised user or system, and credential rotation only denies future interactive logons. It may help prevent subsequent lateral movement via reused credentials, but it does not interrupt active file encryption, stop command-and-control (C2) communication, or halt propagation over SMB. This is a recovery/hardening step, not a containment step, and should be performed after the network path is severed and malicious processes are terminated.

  • ✓

    Isolate the device from the network.

    Why this is correct

    Isolating the device from the network is the immediate containment action because it severs the ransomware's C2 channel, preventing key exchange, additional payload downloads, and SMB-based worm-like propagation to adjacent systems. Physically disconnecting the network cable, disabling the Wi-Fi adapter, or applying a host-based firewall rule to block all inbound and outbound traffic ensures the encryption process cannot phone home or spread. This preserves evidence while stopping the attack in place, making it the first priority in any ransomware containment playbook.

  • ✗

    Run a full antivirus scan.

    Why it's wrong here

    Running a full antivirus scan is not an immediate containment action because it is reactive and time-consuming, and the scan may take minutes to hours while the ransomware continues encrypting files and communicating with its C2 server. Even if the scanner detects and removes the ransomware binary from disk, the malicious processes may be running in memory or injected into trusted system processes (e.g., svchost.exe or powershell.exe), allowing encryption to continue. Containment must happen before or in parallel with scanning; otherwise, the scan only delays critical mitigation and can be overwhelmed by the very malware it is trying to remove.

  • ✓

    Kill the malicious processes.

    Why this is correct

    Killing the malicious processes directly halts the active file-encryption loop, preventing further damage to user data on the local system. This containment action must be performed with precision, using tools like Process Explorer or taskkill, because terminating the wrong process (e.g., a necessary system service) could cause instability, and some ransomware families use process hollowing or inject into legitimate processes to evade termination. While it stops immediate encryption, it must be combined with network isolation to prevent the malware from being re-downloaded or re-executed from a C2 server through the still-open network path.

  • ✗

    Collect the ransomware sample for analysis.

    Why it's wrong here

    Collecting the ransomware sample for analysis is a forensic and investigative step, not a containment action, because it does nothing to stop ongoing encryption, C2 communication, or lateral movement. While preserving the binary is critical for post-incident analysis—such as identifying the family, encryption algorithm, and indicators of compromise—taking time to copy files from an actively infected host delays the two actions that matter: isolating the network path and killing the malicious processes. Sample collection should be performed only after containment is achieved, or from a memory image and disk copy taken with forensic tools, not from the live system during an active outbreak.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.