Courseiva

Three Critical Actions to Contain a Ransomware Incident in Microsoft Sentinel

Your organization uses Microsoft Sentinel and has configured analytics rules for detecting ransomware. You receive an alert indicating possible ransomware activity on a server. Which THREE actions should you take to contain and investigate the incident? (Choose three.)

Quick Answer

The three critical actions to contain a ransomware incident in Microsoft Sentinel are isolating the server from the network using Microsoft Defender for Endpoint, reviewing the incident timeline to understand the attack chain, and running a live response to collect forensic artifacts. Isolating the server immediately cuts off lateral movement, which is the primary goal of containment in a ransomware scenario, while the timeline provides the sequence of events needed to trace the initial compromise, and live response gathers volatile data for deeper investigation. On the SC-200 exam, this question tests your ability to prioritize containment over remediation or detection—common traps include choosing to reset a compromised account password, which fails if the attacker has local persistence, or creating a new analytics rule, which is a detection action, not a containment step. To remember the correct trio, think of the mnemonic “I-T-L”: Isolate, Timeline, Live response—these are the immediate, hands-on actions that stop the spread and preserve evidence before any recovery steps begin.

⚠ Common exam trap

The SC-200 exam often tests the distinction between detection tuning and incident response, and candidates may choose to create new analytics rules or reset passwords instead of taking immediate containment actions like isolation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Initiate a live response session to collect forensic artifacts.

Option B is correct because initiating a live response session in Microsoft Defender for Endpoint lets you run forensic commands (e.g., getfile, analyze, run) on the affected server to collect volatile artifacts such as memory, running processes, and network connections for investigation. Option C is correct because Microsoft Sentinel incidents are integrated with Microsoft 365 Defender, so reviewing the incident timeline provides correlated alerts, entities, and investigation data across endpoints, identities, and email to understand the attack scope. Option E is correct because isolating the server via Microsoft Defender for Endpoint network isolation blocks inbound/outbound traffic (except for Defender communication) to stop ransomware propagation while preserving the ability to investigate. Option A is not appropriate during containment/investigation because creating a new analytics rule is a detection-engineering task, not an incident response action. Option D is not appropriate because resetting the password of the anomalous account is a remediation step that may destroy evidence and does not contain the server-based ransomware activity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a new analytics rule to detect similar behavior.

    Why it's wrong here

    Creating a new analytics rule addresses future detection, not the active ransomware incident, so containment and investigation remain undone. It is tempting because analytics rules are the Sentinel mechanism for spotting threats, and authoring one would be correct when tuning coverage after the incident closes.

  • ✓

    Initiate a live response session to collect forensic artifacts.

    Why this is correct

    Live response connects directly to the affected endpoint, allowing collection of volatile forensic artifacts such as memory, running processes and network connections before they are lost. This satisfies the investigation requirement, gathering evidence needed to determine ransomware scope and persistence mechanisms.

  • ✓

    Review the incident timeline in Microsoft 365 Defender.

    Why this is correct

    Reviewing the incident timeline in Microsoft 365 Defender correlates related alerts, entities and events across the estate, revealing the ransomware's initial access and lateral movement. This satisfies the investigation requirement by building the attack narrative needed to scope containment actions.

  • ✗

    Reset the password of the account that showed anomalous behavior.

    Why it's wrong here

    Resetting the account password disrupts the user's access but leaves the ransomware process on the server running, so containment fails. It is tempting because credential reset is the standard response to compromised accounts, and would be correct if the alert were confirmed identity compromise rather than ransomware execution.

  • ✓

    Isolate the server from the network using Microsoft Defender for Endpoint.

    Why this is correct

    Isolating the server via Microsoft Defender for Endpoint severs network connectivity while preserving the endpoint for investigation, halting ransomware propagation to other hosts. This satisfies the containment requirement, preventing further encryption or lateral spread while forensic work continues.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SC-200

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. During a security incident, a Microsoft Sentinel analytics rule generated an alert for a suspicious sign-in from an unusual location. The incident involves a user whose account has been compromised. The security team needs to take immediate actions to remediate and prevent further damage. Which THREE actions should the security team prioritize?

hard
  • ✓ A.Reset the user's password
  • ✓ B.Revoke the user's session tokens
  • C.Review audit logs for all users
  • D.Raise the user's risk level in Identity Protection
  • ✓ E.Disable the user account in Microsoft Entra ID

Why A: Resetting the user's password (A) is a critical immediate step because it invalidates the current compromised credentials, preventing the attacker from using the known password to authenticate again. In Microsoft Entra ID, a password reset forces the user to create a new credential, which the attacker does not possess, effectively cutting off one of the most common attack vectors.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.