Courseiva

SC-200 Manage a security operations environment Practice Question

You are a security analyst for a company that uses Microsoft Defender XDR. You receive a high-severity incident indicating that a user's device has been compromised with a remote access trojan (RAT). The incident is automatically generated by Microsoft Defender XDR. You need to contain the threat immediately while preserving forensic data. You also need to ensure that the user can continue working with minimal disruption. What should you do?

⚠ Common exam trap

Candidates often choose a reactive remediation step like running a scan or resetting credentials, failing to recognize that immediate containment via network isolation is the priority to stop active compromise while preserving evidence.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Initiate device isolation from Microsoft Defender XDR.

Initiating device isolation from Microsoft Defender XDR immediately disconnects the device from the network while preserving forensic data on the device. This contains the RAT's command-and-control communication without disrupting the user's ability to work offline, and it allows the security team to investigate the compromised device without risk of lateral movement or data exfiltration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Initiate device isolation from Microsoft Defender XDR.

    Why this is correct

    Initiating device isolation in Microsoft Defender XDR severs the endpoint's network connections while preserving its communication path to the Defender service, effectively halting the RAT's command-and-control (C2) channel and preventing lateral movement or data exfiltration. This containment action also preserves the in-memory and on-disk artifacts needed for forensic analysis, since the device remains powered on and untouched. Isolation is the immediate, containment-focused response that limits the attacker's ability to operate while allowing the IR team to investigate and remediate safely.

  • ✗

    Restore the device from a recent backup.

    Why it's wrong here

    Restoring from a recent backup is unreliable for RAT eradication because the backup may itself contain the malicious payload if the infection predates the snapshot, and the restore process commonly overwrites only user data and system files, leaving behind RAT persistence via scheduled tasks, services, or registry run keys. Additionally, restoring a compromised operating system state can reintroduce the very same vulnerability that allowed the initial breach, and it destroys valuable forensic evidence while forcing a disruptive rollback of user settings and recent data changes.

  • ✗

    Run a full antivirus scan on the device.

    Why it's wrong here

    Running a full antivirus scan on an actively compromised host is ineffective because the RAT is specifically engineered to evade signature-based detection—it can detect scanning activity, temporarily disable or hide its processes, or leverage rootkit capabilities to remain invisible to the scanner. The scan operates reactively and does nothing to stop ongoing C2 communication or data theft during the scan window, and the RAT can simply re-infect the system after the scan completes. Moreover, the scan does not contain the threat, leaving the attacker free to escalate privileges or move laterally across the network while the scan runs.

  • ✗

    Reset the user's password and force a sign-out.

    Why it's wrong here

    Resetting the user's password and forcing a sign-out only revokes the human user's access and does nothing to remove the attacker's implant, which typically maintains its own persistence mechanisms such as a service running under SYSTEM or a scheduled task that automatically reestablishes a backdoor. The RAT can also have already captured the user's credentials or created alternate accounts, allowing the attacker to regain access even after credential rotation. This action fails to contain the compromised device itself, leaving the malware active and the network at ongoing risk.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SC-200

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. You are a security analyst at a company that uses Microsoft Defender XDR. You receive an alert about a potential ransomware activity on a workstation. The alert is generated by Microsoft Defender for Endpoint. You need to contain the threat by isolating the workstation from the network while allowing forensic analysis to proceed. You want to use Microsoft Defender XDR's built-in actions. What should you do?

medium
  • A.Create a firewall rule in Microsoft Defender for Cloud Apps to block the device's IP.
  • ✓ B.Use the 'Isolate device' action from the Microsoft Defender XDR portal.
  • C.Unenroll the device from Microsoft Intune.
  • D.Disable the network adapter on the workstation remotely.

Why B: The 'Isolate device' action in Microsoft Defender XDR (specifically from the Microsoft Defender for Endpoint component) disconnects the device from all network traffic except for the Defender for Endpoint service and a few authorized services (such as Windows Update and the Microsoft Update Service). This allows forensic analysis tools (like Live Response) to continue communicating with the device while preventing the ransomware from spreading laterally or communicating with command-and-control servers. This is the built-in, recommended containment action for such scenarios.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.