Courseiva

SC-200 Respond to security incidents Practice Question

You are investigating a potential ransomware incident detected by Microsoft Defender XDR. The incident shows multiple machines with suspicious encryption activity. You need to contain the threat immediately. What should you do first?

⚠ Common exam trap

SC-200 often tests the order of incident response actions, tricking candidates into choosing identity-based actions (password reset, disable account) instead of immediate endpoint containment.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Initiate device isolation on affected machines from Microsoft Defender XDR

In Microsoft Defender XDR, device isolation is the fastest containment action that stops lateral movement and further encryption while preserving the machine for investigation. Isolating affected devices immediately cuts off network communication except for the Defender connection, preventing ransomware from spreading. This is the recommended first step in the incident response containment phase for active ransomware.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Reset the passwords of all users on the affected machines

    Why it's wrong here

    Password resets revoke future authentication but do nothing to stop active encryption or lateral movement from already-compromised sessions. Resetting credentials is correct for confirmed identity compromise, yet ransomware containment requires isolating the affected devices in Microsoft Defender XDR before any credential remediation.

  • ✗

    Run a full antivirus scan on all endpoints

    Why it's wrong here

    A full antivirus scan is detection, not containment, and leaves encryption processes running while it completes. Scanning is appropriate for verifying endpoints after the threat is isolated, but immediate containment requires isolating affected devices through Microsoft Defender XDR so malicious encryption and lateral movement stop at once.

  • ✓

    Initiate device isolation on affected machines from Microsoft Defender XDR

    Why this is correct

    Device isolation severs network connectivity while preserving Microsoft Defender XDR communication, immediately halting lateral spread and further encryption across affected endpoints. This containment satisfies the requirement to stop the threat first, before investigation or remediation, and is executed directly from the incident view.

  • ✗

    Disable the user accounts associated with the affected machines

    Why it's wrong here

    Disabling user accounts addresses credential-based access, not the running encryption processes already executing on the hosts. Account disablement suits suspected compromised identities, whereas ransomware containment demands isolating the affected machines in Microsoft Defender XDR to halt encryption and cut command-and-control traffic.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.