SC-200 Respond to security incidents Practice Question
Your company uses Microsoft Sentinel as its SIEM. You are investigating an incident where a user reported receiving a phishing email that appeared to come from the CEO requesting a wire transfer. The user did not respond. However, the incident also contains alerts from Microsoft Defender for Office 365 indicating that other users clicked on a malicious link in a similar email. The email was sent to 100 users. The company has Microsoft Defender for Endpoint deployed on all devices. The incident requires immediate containment to prevent further compromise. What should you do first?
⚠ Common exam trap
Candidates often confuse containment with investigation or remediation, often choosing to delete the email (D) or isolate a device (C) instead of recognizing that blocking the URL is the fastest way to stop all users from accessing the malicious link, which is the immediate containment priority.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Block the malicious URL using Microsoft Defender for Cloud Apps.
Blocking the malicious URL using Microsoft Defender for Cloud Apps (now part of Microsoft 365 Defender) immediately prevents all users from accessing the phishing link, stopping further compromise at the network level. This is the fastest containment action as it applies a URL block across the tenant without requiring individual mailbox or device actions. The incident involves multiple users clicking the link, so a URL block is the most efficient first step to halt the attack chain.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Run a threat hunting query to find all users who clicked the link.
Why it's wrong here
Threat hunting is a valid step to determine the blast radius, but it does nothing to halt ongoing access to the malicious URL. A KQL query (for example, on UrlClickEvents) takes time and merely documents victims, leaving the URL live and active during the investigation. In the Microsoft Sentinel incident response lifecycle, containment must be executed before deeper reconnaissance, so this option represents a later investigative step, not the immediate action.
- ✓
Block the malicious URL using Microsoft Defender for Cloud Apps.
Why this is correct
Blocking the URL in Microsoft Defender for Cloud Apps immediately prevents any user or device from reaching the phishing destination through the protected web traffic. Microsoft Defender for Cloud Apps uses app proxy and conditional access to enforce URL blocking at the cloud level, covering unmanaged devices and off-network users as well. This is the fastest way to stop the spread of compromise and aligns with the 'contain first' principle in incident response.
- ✗
Isolate the device of the user who reported the email.
Why it's wrong here
Isolating the device of the reporting user is an unnecessary disruption because there is no evidence that the user clicked the malicious link or that their endpoint executed any malicious content. Device isolation should be reserved for confirmed or strongly suspected compromised hosts, and applying it here could harm productivity and escalate the incident without providing security value. The focus should remain on the URL itself, not the messenger.
- ✗
Delete the email from all users' mailboxes using Microsoft 365 Defender.
Why it's wrong here
Deleting the email from all mailboxes removes future opportunities to click, but it does nothing for users who already clicked before the deletion. Microsoft 365 Defender's zero-hour auto purge can be useful for eradication, but it cannot reverse a compromise that has already occurred. In the incident response order, containment via URL blocking must come first because it stops the live threat irrespective of whether mailboxes are cleaned up.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.