Courseiva

SC-200 Respond to security incidents Practice Question

You are a security analyst for a company using Microsoft Defender XDR. An incident is detected involving a device that has been communicating with a known command-and-control (C2) server. The device is currently online and the user is active. What should you do first to contain the threat?

⚠ Common exam trap

Watch out — candidates often choose to kill suspicious processes (Option D) thinking it directly stops the threat, but they overlook that network isolation is the only action that guarantees the C2 channel is severed immediately and completely, regardless of process behavior.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Isolate the device from the network using Microsoft Defender for Endpoint

Isolating the device from the network using Microsoft Defender for Endpoint immediately cuts off all communication with the C2 server, preventing data exfiltration and further command execution. This is the fastest containment action that does not rely on user compliance or process-level responses, and it preserves the device's state for forensic analysis. In an active incident, stopping network-level communication is the priority over scanning or process termination.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Isolate the device from the network using Microsoft Defender for Endpoint

    Why this is correct

    Microsoft Defender for Endpoint's device isolation severs all network connectivity except to the MDE cloud service, instantly breaking command and control channels and laterally used protocols such as SMB and RDP. Because isolation is enforced at the operating system's network stack, it does not rely on killing a process that may simply respawn or on user compliance. This action also preserves volatile memory and active connections for subsequent forensic analysis, making it the preferred first response to a compromised, actively communicating endpoint.

  • ✗

    Run a full antivirus scan on the device

    Why it's wrong here

    Running a full antivirus scan is a reactive step that works against known signatures but does nothing to stop the attacker's current network communication or ongoing lateral movement. While the scan is running, the device remains fully connected to the network, allowing the adversary to exfiltrate data, escalate privileges, or deploy more sophisticated malware that may evade the scanner. Moreover, a scan might take hours, during which the adversary can actively respond to the incident, destroy logs, or move to other hosts, so it should only be used after containment, not as a first response.

  • ✗

    Notify the user to disconnect the device

    Why it's wrong here

    Notifying the user to disconnect the device is dangerous because it immediately alerts the attacker, who may have time to establish additional persistence, delete evidence, or trigger a destructive payload before any coordinated action is taken. Even if the user does physically remove the network cable, the device could remain compromised with dormant threats, and the attacker may already have pivoted to other systems. Additionally, this approach relies on untrained user action under stress, risking incomplete isolation or accidental destruction of forensic artifacts, and it does not integrate with centralized incident response workflows.

  • ✗

    Kill the suspicious processes on the device

    Why it's wrong here

    Killing suspicious processes is insufficient because many advanced attackers use process injection, masquerade as legitimate processes, or install services that automatically restart on termination, so the process may come back immediately. Even if the process is killed, active network sockets and handles can remain open, and other components of the malware may still communicate with the command and control server. Furthermore, terminating a process without first isolating the device can cause the malware to 'fail live' or alert the attacker, and it may destabilize the system, losing valuable in-memory evidence needed for investigation.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.