SC-200 Respond to security incidents • Set 5
SC-200 Respond to security incidents Practice Test 5 — 15 questions with explanations. Free, no signup.
Your Microsoft Defender XDR environment generates an incident indicating that a user's account was used to sign in from an anonymous IP address and then accessed sensitive data in SharePoint Online. After confirming the account is compromised, what should be your first containment step?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.