SC-200 Respond to security incidents Practice Question
Your company uses Microsoft Defender for Endpoint (MDE) on all Windows 10 devices. You are investigating a machine that is suspected of being part of a botnet. The machine is communicating with a known C2 server at IP 203.0.113.55. You have confirmed that the IP is malicious. You need to block all outbound traffic from the machine to that IP immediately, and also ensure that no other devices in the organization can communicate with that IP. The solution must be implemented without deploying additional network appliances. What should you do?
⚠ Common exam trap
SC-200 often tests the difference between Defender for Endpoint custom indicators (IOC-based, tenant-wide, no extra appliances) and Intune/Windows Firewall policies, tricking candidates into picking the more familiar firewall or Intune option when the question explicitly says 'no additional network appliances' and 'all devices'.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a custom network indicator in Microsoft Defender for Endpoint with action 'Alert and block'
Custom network indicators in Microsoft Defender for Endpoint allow you to define IP addresses, URLs, or domains and assign an action of 'Alert and block' or 'Alert only'. When set to 'Alert and block', the indicator is enforced on all onboarded devices via the Defender for Endpoint network protection stack, blocking outbound connections to the specified IP without requiring any additional network appliances. This satisfies both requirements: immediate blocking on the affected machine and organization-wide enforcement across all MDE-onboarded Windows 10 devices.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a network protection policy in Microsoft Intune to block the IP
Why it's wrong here
Network protection in Intune blocks outbound connections by domain or IP through SmartScreen against Microsoft's threat intelligence, and policy delivery is not immediate. It is tempting because it is the supported web-filtering control, but the requirement for immediate, organisation-wide blocking of a confirmed indicator is met by custom indicators in Microsoft Defender for Endpoint.
- ✓
Create a custom network indicator in Microsoft Defender for Endpoint with action 'Alert and block'
Why this is correct
Custom network indicators in Microsoft Defender for Endpoint let you block outbound traffic to a specified IP across all onboarded devices, using the existing agent rather than adding network appliances, satisfying both the immediate block and organisation-wide enforcement.
- ✗
Use the Microsoft Defender for Endpoint portal to block the IP globally
Why it's wrong here
Blocking an IP through the Microsoft Defender for Endpoint portal is achieved by creating an indicator, not by a separate portal block action; the portal alone does not push a block to all devices. It is tempting because indicators are configured there, but the indicator itself, scoped to all devices, is what enforces the block.
- ✗
Create a firewall rule in Windows Defender Firewall to block outbound traffic to the IP, and deploy via Group Policy
Why it's wrong here
A Windows Defender Firewall outbound rule deployed by Group Policy blocks traffic only on devices receiving that GPO, and propagation is slow. It is tempting because it is a familiar host-based control, but the requirement to block the indicator across every onboarded device immediately is satisfied by a custom IP indicator in Microsoft Defender for Endpoint.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SC-200
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. You have detected a suspicious PowerShell command running on several workstations. The command appears to be downloading a payload from a known malicious URL. What is the most effective immediate response using Microsoft Defender for Endpoint?
medium- ✓ A.Add the URL to the custom threat indicator list in Microsoft Defender for Endpoint.
- B.Quarantine the affected workstations.
- C.Enable attack surface reduction rule to block PowerShell scripts.
- D.Initiate a Live Response session to investigate each workstation.
Why A: Adding the URL to the custom threat indicator list in Microsoft Defender for Endpoint is the most effective immediate response because it creates a block indicator that applies to all endpoints in the organization. This action prevents any further downloads from that malicious URL across all workstations, stopping the attack in its tracks without disrupting user productivity or requiring manual intervention on each machine.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.