Courseiva

SC-200 Respond to security incidents Practice Question

Your organization is responding to a ransomware incident. Which TWO actions should be taken first to contain the incident while preserving forensic evidence?

⚠ Common exam trap

SC-200 often tests the balance between containment and evidence preservation, where candidates may choose destructive actions like factory reset or network shutdown, which hinder forensic investigation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Isolate affected devices using Microsoft Defender for Endpoint.

Option A is correct because isolating affected devices through Microsoft Defender for Endpoint (using the "Isolate device" action) severs network communication while keeping the device powered on, so volatile memory and forensic artifacts remain intact for investigation. Option C is correct because disabling compromised user accounts in Microsoft Entra ID immediately blocks the attacker's ability to authenticate, move laterally, or access cloud resources, and it is a reversible containment step that preserves sign-in and audit logs as evidence. Option B is not appropriate as a first action because a blanket password reset across all users is disruptive, does not stop an active session or token-based access, and can destroy or complicate evidence of which accounts were actually compromised. Option D is wrong because a factory reset wipes the device and destroys the forensic evidence needed for the investigation. Option E is wrong because shutting down network switches disrupts the entire segment and business operations, and powering off systems can lose volatile evidence, making it a disproportionate and evidence-destructive containment measure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Isolate affected devices using Microsoft Defender for Endpoint.

    Why this is correct

    Isolating affected devices through Microsoft Defender for Endpoint halts lateral spread and further encryption while keeping the machine powered on, so volatile memory, running processes and network connections remain intact for forensic capture. This directly satisfies the stem's dual constraint: contain the ransomware outbreak yet preserve evidential artefacts.

  • ✗

    Reset passwords for all users in the organization.

    Why it's wrong here

    Mass password resets lock out legitimate users and destroy session evidence, while the attacker's persistence mechanisms remain untouched. It is tempting because credential compromise often accompanies ransomware, making resets feel urgent, and this would be correct after containment, once forensic imaging and scoping confirm which accounts were actually compromised.

  • ✓

    Disable compromised user accounts in Microsoft Entra ID.

    Why this is correct

    Disabling compromised accounts in Microsoft Entra ID immediately blocks the attacker's authentication path, halting further lateral movement and data exfiltration without touching endpoint disk state. This satisfies the containment requirement while preserving volatile and non-volatile forensic evidence, since no host remediation or reimaging occurs before evidence capture.

  • ✗

    Perform a factory reset on all affected devices.

    Why it's wrong here

    A factory reset overwrites disk sectors, destroying volatile memory, logs and file metadata needed for forensic analysis, and it cannot be applied selectively to contain a live threat. It is tempting because it is the standard remediation for repurposing or retiring compromised hardware, where no investigation or evidence retention is required.

  • ✗

    Shut down network switches to isolate the network segment.

    Why it's wrong here

    Powering down switches destroys volatile memory, active sessions and network logs needed for forensics, and may alert the attacker. Segment isolation is achieved through firewall rules or endpoint isolation. Shutting switches would be correct only when immediate total disconnection outweighs evidence preservation.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.