Courseiva

SC-200 Respond to security incidents Practice Question

Your organization uses Microsoft Defender for Endpoint. A user reports that their device is running slowly and exhibiting unusual network activity. You run a live response session and find a suspicious process running. Which action should you take first to contain the threat?

⚠ Common exam trap

SC-200 often tests the ordering of incident response steps — candidates pick 'terminate process' or 'collect memory' because they sound like immediate action, but containment (isolation) must precede eradication and forensic collection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Isolate the device from the network.

The first containment action in a live response session should be to isolate the device from the network. Isolation stops lateral movement, command-and-control communication, and data exfiltration while preserving the device state for forensic investigation. Terminating the process or collecting a memory dump can wait until the device is contained, because the threat may respawn or the attacker may pivot.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Collect a full memory dump for analysis.

    Why it's wrong here

    Collecting a full memory dump preserves evidence but leaves the malicious process executing, so the threat continues spreading during acquisition. It is tempting because forensics values volatile data, but it would be correct once containment has already stopped the process.

  • ✗

    Terminate the suspicious process.

    Why it's wrong here

    Terminating the process destroys volatile evidence such as in-memory code and network connections before collection, and the attacker may simply restart it. It is tempting because it stops immediate execution, but it would be correct after memory and artefacts are captured.

  • ✓

    Isolate the device from the network.

    Why this is correct

    Isolating the device cuts all network communication except the Defender for Endpoint service channel, immediately halting the suspicious process's command-and-control traffic and lateral movement. This satisfies the stem's containment requirement before further investigation, since live response alone leaves the threat active and the device still reachable.

  • ✗

    Add a firewall rule to block outbound traffic from the device.

    Why it's wrong here

    Isolating the device from the network is the containment step; blocking outbound traffic leaves the process running and still able to act locally or via inbound channels. Firewall rules suit persistent egress control across many hosts, not rapid isolation of a single compromised endpoint mid-incident.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.