Courseiva

SC-200 Respond to security incidents Practice Question

Your organization uses Microsoft Defender for Endpoint. An endpoint is detected as infected with a trojan. The analyst needs to isolate the device from the network while preserving forensic data. What action should the analyst take?

⚠ Common exam trap

Candidates often confuse physical network disconnection (Option B) with the controlled, reversible isolation provided by Defender for Endpoint, failing to recognize that forensic preservation and remote management are key requirements in incident response.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Initiate the 'Isolate device' action from the Microsoft Defender XDR portal.

The 'Isolate device' action in Microsoft Defender XDR (formerly Microsoft 365 Defender) disconnects the device from all network traffic except the Defender for Endpoint service, preserving forensic data on the device while preventing the trojan from communicating with command-and-control servers. This action uses a built-in network isolation mechanism that blocks inbound and outbound connections at the OS level, ensuring the device remains accessible for investigation and remediation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Remove the device from the Active Directory domain.

    Why it's wrong here

    Removing a device from the Active Directory domain severs its relationship with domain controllers for authentication and Group Policy, but it does nothing to alter the device's network-facing interfaces or firewall state. The compromised host remains fully capable of communicating with internal systems, so an attacker can continue to spread laterally. Additionally, the removal may interfere with the device's identity for cloud-based services, potentially degrading Defender for Endpoint telemetry and causing further operational disruption.

  • ✗

    Disable the network adapter on the device.

    Why it's wrong here

    Disabling the network adapter at the OS level will stop all traffic, but it also cuts the secure channel that Microsoft Defender for Endpoint uses to receive isolation commands, push indicators, and retrieve forensic evidence. Because the portal can no longer reach the device, you cannot remotely monitor the system or safely reverse the action, potentially leaving the endpoint in an unrecoverable state. It is a brute-force containment that forfeits the visibility required for incident response.

  • ✓

    Initiate the 'Isolate device' action from the Microsoft Defender XDR portal.

    Why this is correct

    The 'Isolate device' action is the designed containment control in Microsoft Defender XDR; it enforces a network-level block on all inbound and outbound communications except for the trusted Defender for Endpoint cloud service, which remains available for management and forensic collection. This preserves your ability to run live response commands, gather evidence, and later release the device from isolation remotely. It is a reversible, evidence-preserving containment that does not require physical access.

  • ✗

    Perform a full reimage of the device.

    Why it's wrong here

    Reimaging the device by reinstalling the operating system wipes the disk and destroys all volatile and forensic evidence, including memory artifacts, logs, and malicious payloads that would be critical for determining the root cause and affected scope. It is a post-incident remediation step, not a containment measure, because it does nothing to stop the attacker from moving laterally to other endpoints while the image is being deployed. Even worse, if the attacker has persisted elsewhere, reimaging a single host gives a false sense of security.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on SC-200

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. You are investigating a potential ransomware incident detected by Microsoft Defender XDR. The incident shows multiple machines with suspicious encryption activity. You need to contain the threat immediately. What should you do first?

medium
  • A.Reset the passwords of all users on the affected machines
  • B.Run a full antivirus scan on all endpoints
  • ✓ C.Initiate device isolation on affected machines from Microsoft Defender XDR
  • D.Disable the user accounts associated with the affected machines

Why C: In Microsoft Defender XDR, device isolation is the fastest containment action that stops lateral movement and further encryption while preserving the machine for investigation. Isolating affected devices immediately cuts off network communication except for the Defender connection, preventing ransomware from spreading. This is the recommended first step in the incident response containment phase for active ransomware.

Variation 2. An incident in Microsoft Defender XDR involves a device that is suspected to be infected with ransomware. The device is online and actively encrypting files. Which action should you take to contain the threat?

medium
  • ✓ A.Isolate the device from the network
  • B.Disable the user's account
  • C.Run a full antivirus scan on the device
  • D.Collect a memory dump from the device

Why A: Isolating the device from the network (Option A) is the correct immediate action because it stops the ransomware from communicating with its command-and-control (C2) server and prevents further lateral movement or encryption of network shares. In Microsoft Defender for Endpoint, device isolation blocks all inbound and outbound traffic at the OS kernel level, while still allowing the device to remain online for forensic analysis and remediation. This containment strategy is critical when the device is actively encrypting files, as it halts the attack's spread without losing the ability to investigate or remediate.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.