SC-200 Respond to security incidents Practice Question
Which TWO actions should you take when handling a confirmed ransomware incident in an environment protected by Microsoft Defender for Endpoint?
⚠ Common exam trap
Candidates often confuse post-incident actions (like submitting samples or reimaging) with immediate containment actions, or mistakenly think disabling real-time protection is a valid response instead of understanding that isolation and indicator blocking are the primary containment steps in MDE.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Block the ransomware file hash using threat intelligence indicators in Microsoft Defender.
Blocking the ransomware file hash via threat intelligence indicators in Microsoft Defender for Endpoint (MDE) immediately prevents further execution of that known malicious file across all endpoints in the environment, leveraging the built-in TI indicator feature. Option B is correct because initiating device isolation from the MDE console disconnects the affected device from the network while maintaining connectivity to the MDE service, containing the spread of ransomware without losing visibility or control.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Block the ransomware file hash using threat intelligence indicators in Microsoft Defender.
Why this is correct
Blocking the ransomware executable's SHA-256 hash via Microsoft Defender for Endpoint custom indicators immediately prevents that specific binary from running on any monitored endpoint, independent of signature updates. Because the hash is a known-bad IOC, defining it as a block indicator enforces a deny action at the kernel and network layers, halting execution on already-uninfected devices and stopping the ransomware from propagating through mapped shares.
- ✓
Initiate device isolation from the Microsoft Defender for Endpoint console.
Why this is correct
Initiating device isolation from the Microsoft Defender for Endpoint console severs all inbound and outbound communication from the affected machine (except the MDE cloud service) while leaving the host powered on. This active containment step stops lateral movement, C2 callbacks, and further file-encryption activity, while preserving memory state and event logs for forensic analysis. Isolation is preferred over unplugging the machine because it maintains a managed, monitored channel.
- ✗
Disable Windows Defender real-time protection.
Why it's wrong here
Disabling Windows Defender real-time protection would disable the agent's ongoing malware prevention at the moment you most need it, exposing the environment to follow-on payloads and allowing the ransomware to modify system files unimpeded. This action actively degrades defense-in-depth and could be exploited by adversaries as a security control bypass; it is the opposite of an effective containment response.
- ✗
Submit the ransomware sample to Microsoft for analysis.
Why it's wrong here
Submitting the ransomware sample to Microsoft's analysis pipeline is a valuable intelligence-sharing activity that can improve global detections, but the resulting signature or cloud reputation update takes time and does nothing to contain the active infection on your network. Immediate response priorities must be isolating the endpoint and blocking the specific indicator of compromise; sample submission is a post-containment investigation step, not a first responder action.
- ✗
Reimage all affected servers immediately.
Why it's wrong here
Immediately reimaging affected servers destroys volatile forensic evidence—such as memory-resident malware, open network connections, and the ransomware's initial access vector—that incident responders need to determine the blast radius and remove the root-cause foothold. This approach is a cleanup step that should be executed only after containment, evidence collection, and a clear understanding of the attack chain; doing it first can enable re-infection if the entry point is still present.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.