SC-200 Respond to security incidents Practice Question
Your organization uses Microsoft Sentinel and Microsoft Defender for Cloud. A critical server in Azure was compromised by ransomware. The incident response team needs to ensure that no other resources in the same resource group are affected. What is the most immediate containment action?
⚠ Common exam trap
A common mix-up: candidates choose to delete or move the VM, not realizing that immediate network isolation is the fastest way to contain lateral movement while preserving evidence for investigation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Disable the public IP address and apply an NSG rule to block all inbound/outbound traffic to the server's subnet.
The most immediate containment action is to isolate the compromised server's subnet by disabling its public IP and applying an NSG rule that blocks all inbound and outbound traffic. This prevents lateral movement of ransomware to other resources in the same resource group while preserving the VM for forensic analysis. In Microsoft Defender for Cloud and Sentinel, network isolation at the subnet level is the fastest way to contain a breach without destroying evidence.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Delete the virtual machine immediately to stop the ransomware.
Why it's wrong here
Deleting the virtual machine immediately is an extreme and irreversible action that destroys all volatile and on-disk evidence essential for forensic analysis and root-cause identification in Microsoft Sentinel. It also fails to contain the incident because if the adversary used lateral movement, ransomware can already be executing on other hosts. Furthermore, deletion does not stop malware processes that may persist elsewhere, and dependent workloads can be disrupted, so this is never a first-line containment step.
- ✓
Disable the public IP address and apply an NSG rule to block all inbound/outbound traffic to the server's subnet.
Why this is correct
Disabling the public IP and applying an NSG rule that blocks all inbound and outbound traffic at the server's subnet effectively isolates the VM from both external attackers and internal lateral movement while leaving the machine powered on for evidence preservation. Because NSGs are stateful and evaluated for every flow, this drops current network conversations and prevents new ones, cutting off command-and-control or data exfiltration. This is the proper immediate containment action in an incident response playbook, as it contains the threat without destroying forensic artifacts.
- ✗
Change the local administrator password on the VM.
Why it's wrong here
Changing the local administrator password is a credential-reset activity that does nothing to stop the ransomware process that is already running in memory or its ongoing file-encryption and network-communication actions. The malware may have escalated to a service account, injected into a system process, or persisted through scheduled tasks, so rotating the local account only affects future interactive logons. Since the current process' access token is already issued, it continues to operate; thus, this is a long-term hardening step, not containment.
- ✗
Move the VM to a different virtual network and subnet.
Why it's wrong here
Moving the virtual machine to a different virtual network and subnet requires stopping and deallocating the VM, which is a slow and disruptive process that does not interrupt the ransomware process already executing in memory. During the move, any network flows that were established before the new NSGs are applied may remain unaffected, and the attacker can continue to pivot to other resources. Additionally, the move itself changes the VM's configuration but does not apply any new security controls unless explicitly configured, so it fails as an immediate containment measure.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SC-200
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Your organization uses Microsoft Sentinel and Microsoft Defender for Cloud. During an incident, you need to automatically disable a compromised Azure VM from the network. Which playbook action should you use?
hard- A.Apply an Azure Policy to deny network changes.
- B.Create an Azure Firewall rule to block the VM's IP.
- ✓ C.Add a rule to the VM's network security group to deny all traffic.
- D.Remove the VM's role assignment from Azure RBAC.
Why C: Adding a rule to the VM's network security group (NSG) to deny all traffic is the most direct and immediate way to isolate a compromised Azure VM at the network level. NSG rules are evaluated in order of priority, and a deny-all rule (e.g., denying any inbound and outbound traffic) effectively cuts off all network communication to and from the VM, which is a common containment step during incident response. This action can be automated via a Microsoft Sentinel playbook using the Azure Network Security Group connector.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.