SC-200 Respond to security incidents • Set 15
SC-200 Respond to security incidents Practice Test 15 — 15 questions with explanations. Free, no signup.
Your organization uses Microsoft Sentinel. You are responsible for responding to incidents. A new 'MFA Denied' incident is created from Microsoft Entra ID sign-in logs, indicating that a user in your organization had multiple MFA denials from a suspicious IP address (203.0.113.5). The user is a sales representative who frequently travels. The incident severity is Medium. The incident contains entities: user 'jsmith@contoso.com', IP address 203.0.113.5, and a device running Windows 11. You need to investigate and determine if this is a true positive. The user is currently on a business trip in Europe, but the sign-in attempts originated from an IP address in a different region. What should you do first?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.