MS-900 Describe Microsoft 365 apps and services Practice Question
Your organization uses Microsoft 365 E5 and experiences a security incident where a user's account is compromised. You need to immediately prevent the attacker from accessing Microsoft 365 services while preserving the user's data for investigation. Which action should you take?
⚠ Common exam trap
Many candidates confuse 'revoke sessions' (which only kills current sessions but allows re-authentication) with 'block sign-in' (which prevents all future authentication), leading them to choose Option C as a quick fix without realizing the attacker can simply log back in.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Block sign-in for the user in Microsoft Entra ID
Blocking sign-in for the user in Microsoft Entra ID immediately prevents the attacker from authenticating to any Microsoft 365 service, while the user's data remains intact in Exchange Online, SharePoint, and OneDrive for forensic analysis. This action does not delete or alter any data, preserving the full investigation trail.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Block sign-in for the user in Microsoft Entra ID
Why this is correct
Blocking sign-in in Microsoft Entra ID flips the user account to a disabled state (Sign-in enabled = No), which immediately rejects all new authentication requests for Entra ID and Microsoft 365 services. This prevents the attacker from obtaining any additional access tokens, and while previously issued tokens may remain technically valid until expiration, most resource access attempts will fail on the next revalidation. Crucially, this action preserves all user data such as mailbox and OneDrive contents, allowing forensic investigation without any deletion of evidence.
- ✗
Delete the user account from Microsoft Entra ID
Why it's wrong here
Deleting the user account from Microsoft Entra ID is a destructive, irreversible action that marks the user object for removal and triggers the gradual deletion of associated resources like the Exchange Online mailbox, OneDrive, and Teams files. Although Microsoft 365 retains a soft-deleted user for up to 30 days, the account is immediately disassociated from its data, and restoring it becomes a complex recovery operation. This destroys or suspends forensic artifacts and audit trails needed to investigate the incident, so it is never an appropriate containment step.
- ✗
Revoke the user's sessions using Microsoft Entra ID
Why it's wrong here
Revoking the user's sessions via the 'Revoke sessions' button in Microsoft Entra ID invalidates the user's current refresh tokens and forces clients to re-authenticate, but it does not disable the account itself. An attacker who has the user's password or other credentials can simply sign in again, and any access tokens already cached on compromised devices may remain valid until they expire. This is a temporary mitigation that helps terminate existing activity but fails as a standalone preventive measure against repeat compromise.
- ✗
Reset the user's password
Why it's wrong here
Resetting the user's password changes the credential for future interactive authentication, but it does not invalidate existing access tokens or refresh tokens already issued to the attacker. Those tokens continue to grant access to Microsoft 365 APIs and services until their natural expiry or until an explicit token revocation is performed. Thus, password reset alone leaves the door open for the attacker to persist, making it an insufficient immediate containment action compared to blocking sign-in.
Go deeper
Related to this question
Learn chapter
SharePoint Modern Sites vs Classic Sites
Key term
User
A user is any person, system, or device that interacts with an IT service, resource, or identity system, typically authenticated through credentials and authorized to perform specific actions.
Key term
Microsoft Entra ID
Microsoft Entra ID is a cloud-based identity and access management service that lets employees sign in and access resources both inside and outside of your organization.
About these practice questions
Courseiva writes every MS-900 question from scratch — 794 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.