SC-200 Respond to security incidents • Set 26
SC-200 Respond to security incidents Practice Test 26 — 15 questions with explanations. Free, no signup.
A security analyst detects a suspicious sign-in from an unusual location using Microsoft Entra ID. The user has not enabled MFA. Which action should the analyst take first to investigate and potentially contain the incident?