SC-200 Respond to security incidents Practice Question
You are a security analyst investigating a detected phishing campaign targeting users in your organization. The Microsoft Defender for Office 365 alert indicates that several users clicked on a malicious link. Which action should you take first to prevent further compromise?
⚠ Common exam trap
Watch out — candidates often confuse incident response containment steps (like device isolation) with the most immediate preventive action, failing to recognize that blocking the malicious URL at the endpoint level stops the attack vector for all users without the operational impact of isolating devices.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add the malicious URL to the Microsoft Defender for Endpoint custom threat indicator list.
Adding the malicious URL to the Microsoft Defender for Endpoint custom threat indicator list is the correct first action because it immediately blocks future access to that URL across all endpoints protected by Defender for Endpoint, preventing further compromise from users clicking the same link. This leverages the threat intelligence feed to enforce a block action at the network level, stopping the attack vector proactively without disrupting user productivity or requiring device isolation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Add the malicious URL to the Microsoft Defender for Endpoint custom threat indicator list.
Why this is correct
Creating a custom threat intelligence indicator for the malicious URL in Microsoft Defender for Endpoint triggers an immediate Alert/Block enforcement action on all onboarded endpoints via the built-in Network Protection component. When any user clicks the link, the endpoint blocks outbound connectivity to that URL before the content loads, regardless of the fact that the phishing email is already sitting in their mailbox. This is the fastest operational control because it addresses the actual click vector across all affected devices, not just the email envelope, and can also generate an alert for incident investigation.
- ✗
Isolate all affected users' devices from the network.
Why it's wrong here
Using Microsoft Defender for Endpoint device isolation cuts off all network communications except to the Defender for Endpoint cloud service, which severely disrupts user workflows and server operations. At this stage there is no evidence that the devices have been compromised or are actively acting as a beacon, so isolating every affected workstation 'just in case' is a disproportionate response. The remediation should first neutralize the malicious URL and enable the security team to detect any actual exploitation, then isolate only the specific devices showing signs of threat activity.
- ✗
Report the email to Microsoft for analysis.
Why it's wrong here
Submitting the phishing email to Microsoft for analysis contributes signal to the mailbox intelligence pipeline and may improve filtering for future campaigns, but it does not remove the already-delivered email from any recipient's Inbox or block the embedded link from being clicked. Microsoft's analyst response or backend rule generation takes time to propagate, so there is no immediate containment effect on currently exposed users. In the meantime, users can still access the malicious destination because the original message remains actionable.
- ✗
Block the sender email address in the tenant.
Why it's wrong here
Blocking the sender's email address using a transport rule or tenant-level block list prevents new inbound messages that originate from that exact address, but it has no retroactive effect on emails already delivered to inboxes. Since the phishing URL is already present in existing messages, recipients can still click it and trigger the attack; the block simply stops future variations from the same sender. Attackers also frequently rotate sender addresses and domains, so relying on this control yields no coverage over other infrastructure used in the same campaign.
Go deeper
Related to this question
About these practice questions
One of 209 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.