Courseiva

SC-200 Respond to security incidents Practice Question

You are responding to a ransomware incident in Microsoft Defender XDR. You have identified that the malware encrypted files on several devices and then deleted the volume shadow copies. Which of the following actions should you take first to contain the incident?

⚠ Common exam trap

Watch out — candidates often confuse containment with remediation, choosing to delete malware or run scans first, but the SC-200 exam emphasizes that immediate isolation is the priority to stop lateral spread before any cleanup or recovery actions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Isolate affected devices using Microsoft Defender for Endpoint

Isolating affected devices using Microsoft Defender for Endpoint is the correct first action because it immediately cuts off network communication, preventing the ransomware from spreading laterally to other devices and stopping further encryption or deletion of shadow copies. Containment must precede remediation to limit the blast radius, and Defender for Endpoint's device isolation feature achieves this at the network level without requiring physical disconnection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Run a remediation action to delete the detected malware

    Why it's wrong here

    Deleting the detected malware file through a remediation action addresses only the artifact, not the damage already done. In a ransomware incident, the encryption of user data has already occurred, and removing the binary does not reverse cryptographic changes or recover files. Furthermore, active ransomware often operates via multiple processes or persists in memory, so a single delete action fails to contain lateral movement or stop further encryption across endpoints.

  • ✗

    Restore encrypted files from backup

    Why it's wrong here

    Restoring encrypted files from backup is a recovery-phase step that must occur only after the environment is contained and the attacker is evicted. If you restore while ransomware is still active, the restored files can be immediately re-encrypted, and backups that are reachable from infected hosts may also be compromised. Effective incident response dictates containment — isolating affected devices — before any restoration effort, to ensure the integrity of the restored data.

  • ✗

    Run a full antivirus scan on all devices

    Why it's wrong here

    A full antivirus scan is a detection and eradication activity, not a containment measure, and it cannot stop the spread of ransomware in real time. Scanning all devices is time-consuming, and during that window the active ransomware may continue encrypting files or moving laterally to other endpoints. In an active incident, you must first isolate confirmed affected devices to prevent propagation, then use scans to scope and clean the environment.

  • ✓

    Isolate affected devices using Microsoft Defender for Endpoint

    Why this is correct

    Isolating affected devices using Microsoft Defender for Endpoint is the correct first step because it immediately blocks all incoming and outgoing communication to and from the compromised host, cutting off the ransomware's ability to spread laterally and communicate with command-and-control servers. This action preserves forensic evidence while containing the attack, and it can be initiated remotely from the MDE console without requiring physical access or disrupting the rest of the network. Full isolation still allows the Defender service to communicate, so security teams can continue to investigate and remediate the endpoint.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on SC-200

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Your organization uses Microsoft Defender for Endpoint. A user reports that their device is running slowly and exhibiting unusual network activity. You run a live response session and find a suspicious process running. Which action should you take first to contain the threat?

medium
  • A.Collect a full memory dump for analysis.
  • B.Terminate the suspicious process.
  • ✓ C.Isolate the device from the network.
  • D.Add a firewall rule to block outbound traffic from the device.

Why C: The first containment action in a live response session should be to isolate the device from the network. Isolation stops lateral movement, command-and-control communication, and data exfiltration while preserving the device state for forensic investigation. Terminating the process or collecting a memory dump can wait until the device is contained, because the threat may respawn or the attacker may pivot.

Variation 2. You are investigating a potential ransomware incident in Microsoft Defender XDR. The incident has a high severity alert indicating that a user installed a suspicious application. Which initial response action should you take to contain the threat while preserving evidence?

medium
  • ✓ A.Isolate the device using Microsoft Defender for Endpoint.
  • B.Reset the user's password and enforce MFA.
  • C.Uninstall the suspicious application via Intune.
  • D.Disable the user account in Microsoft Entra ID.

Why A: Isolating the device using Microsoft Defender for Endpoint immediately stops lateral movement and data exfiltration while preserving forensic data. Option B is wrong because resetting the password and enforcing MFA does not contain the threat on the device itself. Option C is wrong because uninstalling the suspicious application may remove evidence needed for investigation. Option D is wrong because disabling the user account does not stop malware already running on the device.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.