Courseiva

SC-200 Respond to security incidents Practice Question

Your security team receives an alert from Microsoft Defender for Endpoint indicating a suspicious PowerShell command was executed on a device. The command attempted to download a payload from a known malicious IP. After confirming the alert is a true positive, what should be your first containment step?

⚠ Common exam trap

The trap is choosing an investigative or identity-focused action (hunting, disabling account, resetting password) as the 'first' step when the question asks for containment — candidates conflate investigation with containment and miss that stopping the active threat takes priority.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Isolate the device from the network using Microsoft Defender for Endpoint

Isolating the device via Microsoft Defender for Endpoint is the correct first containment step because it immediately cuts the endpoint off from the network while preserving the Defender agent's communication channel for further investigation and remediation. This stops lateral movement and C2 traffic from the compromised host without destroying forensic evidence. It is the standard 'contain first, investigate second' playbook for confirmed endpoint compromise.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Search for similar commands across all devices using advanced hunting

    Why it's wrong here

    Advanced hunting queries telemetry retrospectively; it cannot sever the active command-and-control channel or isolate the compromised endpoint, so the payload download proceeds. It is tempting because hunting is the right first move for scoping an incident's blast radius across devices — but containment must precede investigation, which is why isolating the device is correct here.

  • ✗

    Disable the user account in Microsoft Entra ID

    Why it's wrong here

    Disabling the Microsoft Entra ID account does not stop the already-running malicious process on the device, which could continue downloading and executing payloads. Account disablement suits suspected credential compromise or impossible-travel sign-ins, where identity, not endpoint execution, is the threat vector.

  • ✓

    Isolate the device from the network using Microsoft Defender for Endpoint

    Why this is correct

    Isolation immediately cuts the device's network connectivity, halting any further command-and-control communication or payload download from the malicious IP. This contains the true-positive compromise before lateral movement or additional payloads occur, satisfying the requirement for a first containment step.

  • ✗

    Reset the user's password

    Why it's wrong here

    Resetting the password addresses credential compromise, not an active malicious process on the endpoint. The payload download continues regardless of credential state. Password reset suits suspected identity compromise, such as a leaked credential or impossible-travel sign-in. Here, isolating the device stops the running PowerShell command and blocks further command-and-control communication.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.