Courseiva

SC-200 Respond to security incidents Practice Question

Your organization uses Microsoft 365 Defender. You are investigating a potential malware outbreak on several endpoints. Which TWO actions should you take to isolate affected devices and prevent lateral movement?

⚠ Common exam trap

Many candidates confuse reactive remediation actions (like scanning or password resets) with proactive containment actions, failing to recognize that only network-level isolation and indicator blocking directly prevent lateral movement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use Microsoft Defender for Endpoint to initiate device isolation on affected devices.

Microsoft Defender for Endpoint's device isolation feature disconnects the device from the network while keeping the endpoint connected to the Defender service for monitoring and remediation. This prevents lateral movement by stopping all inbound and outbound communication, effectively containing the malware without losing visibility or control.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use Microsoft Defender for Endpoint to initiate device isolation on affected devices.

    Why this is correct

    Device isolation should be initiated from the Microsoft 365 Defender portal on each affected endpoint. This action immediately blocks all inbound and outbound network communications, except traffic to the Defender service, so the attacker loses the ability to move laterally, communicate with command-and-control servers, or exfiltrate data while the investigation continues. It is the first-line containment control when an active infection is confirmed.

  • ✗

    Run a full antivirus scan on all endpoints.

    Why it's wrong here

    Running a full antivirus scan is a passive, detection-centric action that depends on signatures, heuristics, or cloud protection and does not alter the network state. While the scan runs, malware already active in memory can continue to spread, and scanning all endpoints can create resource contention without cutting off attacker connectivity, so it is not an immediate containment control.

  • ✗

    Reset the passwords of all users on the affected devices.

    Why it's wrong here

    Resetting passwords only invalidates stored credentials; however, lateral movement attacks often rely on Kerberos ticket-granting tickets, NTLM hashes, cached session tokens, or remote service execution that do not require a current password. Additionally, resetting every user password on affected devices disrupts legitimate operations and does nothing to stop a malware process that is already running on the compromised hosts.

  • ✗

    Delete the user accounts that logged into the affected devices.

    Why it's wrong here

    Deleting the user accounts that logged into affected devices is a drastic, identity-focused action that fails to address the underlying malware execution or its active network connections. It removes potentially valuable forensic artifacts such as profile data, may break application dependencies or domain trust, and still does not prevent the malicious binaries from being executed again by other means, making it an excessive and ineffective containment step.

  • ✓

    Block the file hash of the malware in Microsoft Defender for Endpoint indicators.

    Why this is correct

    Adding the malware's file hash as an Indicator of Compromise in Microsoft Defender for Endpoint indicators with a block action enables the security team to enforce a hard stop on execution of that specific file across all onboarded endpoints. This is a correct preventive measure because it stops new machines from running the known malware and helps contain the outbreak, although it should be paired with device isolation because the hash alone does not terminate processes already running on compromised hosts.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.