SC-200 Respond to security incidents • Set 16
SC-200 Respond to security incidents Practice Test 16 — 15 questions with explanations. Free, no signup.
Your organization uses Microsoft Defender for Cloud Apps and Microsoft Sentinel. An alert indicates that an external IP address is downloading large amounts of data from a SharePoint site containing confidential documents. The activity is coming from a valid user account that appears to be compromised. What should you do first to stop the data exfiltration?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.