Courseiva
Perform threat hunting →mediumMultiple Choice

SC-200 Perform threat hunting Practice Question

Your threat hunt identifies a process that is making outbound connections to an unknown IP address. Which Microsoft Defender for Endpoint action can you take to immediately isolate the device?

⚠ Common exam trap

SC-200 often tests the distinction between actions that contain a threat (like isolation) versus those that only gather data or remediate files, so candidates must recognize that only 'Isolate device' immediately stops network communication.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Isolate device

The 'Isolate device' action in Microsoft Defender for Endpoint immediately cuts off a device from all network communication except for the Defender for Endpoint service itself, preventing the malicious process from exfiltrating data or communicating with command-and-control servers. This is the only action that provides immediate network isolation while preserving the ability to remotely investigate and remediate the device. Other actions like collecting an investigation package or running an antivirus scan do not stop active outbound connections.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Isolate device

    Why this is correct

    Isolate device — Immediately disconnects the device from the network via Microsoft Defender for Endpoint's containment action, severing all inbound and outbound traffic while keeping the device powered on for forensic preservation. This is the correct first response to a process making outbound connections because it stops active data exfiltration and lateral movement without rebooting or losing volatile evidence, and it can be applied selectively if needed.

  • ✗

    Collect investigation package

    Why it's wrong here

    Collect investigation package — Gathers a comprehensive forensic bundle including process memory, network connections, registry keys, and files, but it does not alter the device's network state or terminate the suspicious process. The outbound connection continues, allowing the threat to persist and potentially communicate with command-and-control infrastructure, making this a supplementary evidence-gathering action rather than a containment measure.

  • ✗

    Block file

    Why it's wrong here

    Block file — Adds a file hash indicator of compromise to block future execution of the specific binary, but this does not affect a process already running in memory or the established outbound connection. Attackers often use fileless techniques or living-off-the-land binaries, so blocking one file may be sidestepped and fails to provide the immediate network-level containment required for an active beaconing host.

  • ✗

    Run antivirus scan

    Why it's wrong here

    Run antivirus scan — Performs a signature-based and heuristic scan to detect and remediate malicious files, but it operates at the file-system layer and typically cannot kill an already executing process or stop active network traffic. The scan's duration leaves the compromised device fully connected, and many sophisticated threats evade traditional antivirus detection, making this an unsuitable first response to an urgent outbound connection indicator.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.