Courseiva

SC-200 Respond to security incidents Practice Question

Which TWO actions should you take when responding to a confirmed ransomware incident in Microsoft Defender for Endpoint?

⚠ Common exam trap

The trap here is that candidates often prioritize forensic collection (Option C) or file deletion (Option E) over immediate containment, not realizing that isolation and scanning are the mandated first steps in the Microsoft Defender for Endpoint ransomware response playbook.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Run a full antivirus scan on the affected devices.

Running a full antivirus scan on affected devices helps identify and remove any remaining ransomware artifacts or secondary payloads that may not have been detected during the initial response. In Microsoft Defender for Endpoint, a full scan leverages the cloud-delivered protection and behavior monitoring to thoroughly examine all files and processes, reducing the risk of reinfection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Run a full antivirus scan on the affected devices.

    Why this is correct

    Running a full antivirus scan on affected devices is a primary eradication step because it identifies known ransomware signatures, quarantines the malicious binary, and cleans any dropped files or artifacts. In the context of Microsoft Defender for Endpoint, the scan leverages cloud-delivered protection and tamper protection to remove the threat from all local drives. This action is most effective after isolating the device, because the scan itself does not prevent lateral movement while it is running.

  • ✗

    Allow the ransomware executable in the firewall.

    Why it's wrong here

    Permitting the ransomware executable through the firewall would actively allow outbound command-and-control (C2) traffic and inbound SMB connections that the malware uses to propagate, directly undermining containment. Firewall rules should be configured to block the executable's traffic, and the incident response process should include adding indicators of compromise (IOCs) to block lists. Allowing a known malicious binary is the opposite of a containment action and would accelerate the spread.

  • ✗

    Collect an investigation package from the affected devices.

    Why it's wrong here

    Collecting an investigation package from affected devices (such as memory dumps, event logs, and forensic artifacts) is a valuable step for later root-cause analysis, but it does not contain an active ransomware outbreak. The collection process can be time-consuming and might modify system state, and it does not stop the malware from encrypting additional files or connecting to its C2 server. Proper incident response sequencing prioritizes isolation and eradication before forensic collection, or collects from an isolated snapshot.

  • ✓

    Isolate the affected devices from the network.

    Why this is correct

    Isolating affected devices from the network is a critical containment action that immediately severs the ransomware's ability to move laterally via SMB, RDP, or other network protocols and blocks communication with its command-and-control infrastructure. This can be done through Defender for Endpoint's device isolation feature, which restricts the device's network connectivity while still allowing it to send telemetry to the security portal. Containment is the first priority in incident response because the speed of spread is more dangerous than the encryption itself.

  • ✗

    Initiate a live response session to delete files.

    Why it's wrong here

    Initiating a live response session to delete files is an advanced remediation measure that should not be the first action, because it requires careful planning to avoid leaving behind persistence mechanisms like scheduled tasks, services, or registry run keys. Live response also operates over the network, and if the device is not already isolated, the session itself could be disrupted or the ransomware could continue spreading. It is most appropriate after containment, when you can also collect forensic data and use more thorough removal techniques.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.