Courseiva

SC-200 Respond to security incidents Practice Question

Your organization uses Microsoft Defender for Cloud to monitor hybrid workloads. You receive an alert that a fileless malware attack was detected on an on-premises server connected via Azure Arc. The server is running Windows Server 2019. What is the BEST action to contain the threat?

⚠ Common exam trap

Many candidates confuse 'containment' with 'remediation' and choose a long-term fix like patching or restarting, rather than the immediate network isolation required to stop an active fileless attack.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Run a script via Azure Arc to disable the network interfaces on the server.

Disabling the network interfaces via Azure Arc immediately cuts off the compromised server's network connectivity, preventing lateral movement or data exfiltration by the fileless malware. Since fileless malware operates in memory and may not leave persistent artifacts, containment via network isolation is the fastest and most effective initial response.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Apply a security update using Azure Update Manager.

    Why it's wrong here

    Applying a security update via Azure Update Manager only patches underlying OS vulnerabilities; it cannot remove an active fileless threat that is already executing in memory. Fileless malware typically leverages built-in tools such as PowerShell or WMI, so the vulnerability being patched may not even be the entry point used. Update Manager also lacks the ability to terminate malicious processes, block C2 traffic, or isolate the server, meaning the attacker's foothold remains intact. Therefore, this action fails to contain the ongoing attack.

  • ✓

    Run a script via Azure Arc to disable the network interfaces on the server.

    Why this is correct

    Running a script via Azure Arc to disable the network interfaces is a network-based containment action that immediately cuts off all inbound and outbound traffic on the server. By using the Azure Arc 'Run Command' or a custom script extension, the server's NICs are brought down, which blocks data exfiltration, lateral movement, and command-and-control communication with the attacker's infrastructure. This preserves the machine in its current state for forensic analysis while the fileless malware is isolated from the rest of the network. It is an effective first response because it neutralizes the attacker's ability to communicate without disabling management channels.

  • ✗

    Use Azure Automation runbook to restart the server.

    Why it's wrong here

    Restarting the server with an Automation runbook only clears volatile memory (RAM), and many fileless malware strains persist by writing to the registry, creating scheduled tasks, or installing WMI event subscriptions. After reboot, these persistence mechanisms reload the payload and restart the attack, so the runbook provides no lasting containment. Additionally, an Automation runbook does not collect forensic data, block network traffic, or mitigate running processes; it simply cycles the OS, which may even give a malicious loader a fresh, clean execution. Thus, a restart is an unreliable response to an active fileless compromise.

  • ✗

    Uninstall the Azure Arc agent from the server to isolate it.

    Why it's wrong here

    Uninstalling the Azure Arc agent severs the server's management plane connection, so Microsoft Defender for Cloud can no longer deliver alerts, collect security events, or invoke response actions on the machine. This uninstall does not remove or stop the fileless malware, nor does it disable any network interfaces—the server stays accessible to attackers and can still be used for lateral movement. You would lose all visibility and live response capability at the exact moment containment is needed, making the situation more dangerous. The agent is the essential channel for executing the very remediation script that could isolate the host.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.