Courseiva

SC-200 Respond to security incidents Practice Question

Your organization uses Microsoft Defender XDR. You receive an alert about a potentially unwanted application (PUA) being installed on a device. The PUA is not blocked by your current policy. You need to prevent future installations of this PUA without affecting other software. What should you do?

⚠ Common exam trap

A common mix-up: candidates choose Option A, thinking that enabling PUA blocking is the simplest solution, but they overlook the requirement to avoid affecting other software, which makes the broad policy change inappropriate.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a custom indicator of compromise (IoC) to block the specific file's hash.

Creating a custom indicator of compromise (IoC) with the specific file hash allows you to block only that exact PUA file without affecting other software. This leverages Microsoft Defender for Endpoint's custom IoC capability to override the default PUA detection policy, targeting the specific file hash rather than enabling a broad block on all PUAs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable blocking of all potentially unwanted applications in the antivirus policy.

    Why it's wrong here

    Enabling blocking of all potentially unwanted applications in the antivirus policy is overly broad: Microsoft's PUA classification may not align with your organization's approved software list, and it can block legitimate internal tools, causing false positives and operational disruption. This policy-level setting applies globally across all devices rather than targeting the specific file hash, and it does not directly remediate active installations or provide a scoped, incident-specific response.

  • ✗

    Reset the device to its factory settings.

    Why it's wrong here

    Resetting the device to factory settings is an extreme containment step that wipes all data, installed applications, and configurations, leading to significant downtime and potential data loss. Even if the reset succeeds, it does not address the root cause, prevent the user from reinstalling the same PUA from the same delivery vector, or provide any reputation or execution block for that file across the environment. Microsoft Defender XDR incident response calls for precise, targeted actions like blocking the specific indicator, not a full reimage.

  • ✓

    Create a custom indicator of compromise (IoC) to block the specific file's hash.

    Why this is correct

    Creating a custom indicator of compromise (IoC) for the specific file hash, with the action set to Block and remediate, is the precise and recommended response. This indicator is propagated to all devices through Microsoft Defender XDR, preventing the file from executing and automatically triggering remediation of existing copies on any onboarded endpoint. Because the block is scoped solely to that file hash, legitimate applications are preserved, avoiding false positives, and the defense persists for future attempts to execute or download the file.

  • ✗

    Run a full scan on the device to remove the PUA.

    Why it's wrong here

    Running a full scan on the device may detect and remove the currently present PUA, but it is a reactive measure that does nothing to prevent the file from being downloaded or executed again in the future. The scan does not establish a permanent policy or indicator that blocks the file across the environment, nor does it disrupt the delivery channel or the user's ability to reacquire the PUA. Additionally, a full scan can be time-consuming and may miss the file if it is hidden or persists in a different location, whereas a hash-based IoC provides an immediate, environment-wide control.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.