SC-200 Respond to security incidents Practice Question
A company uses Microsoft Defender XDR and has enabled automatic attack disruption for human-operated ransomware. During an incident, the system automatically contains a compromised account. However, the SOC team wants to ensure that the containment action is reversible and that the account can be restored after investigation. What should the team do before restoring the account?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Change the account's password and enable multi-factor authentication.
After automatic containment disables a compromised account, the SOC team must change its password and enable multi-factor authentication before restoring it. This ensures the attacker cannot regain access with stolen credentials. Option B is a good practice but not a prerequisite for restoring this specific account. Option C is unnecessary if the account was not an administrator. Option D is irrelevant because containment applies to the account, not devices.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Change the account's password and enable multi-factor authentication.
Why this is correct
Resetting the account's password invalidates the compromised credentials that an attacker may be using, and enabling MFA adds a second authentication layer that blocks unauthorized re-entry. This is the required remediation step before restoring the account because it directly addresses the known compromise of the identity itself. Without this step, any restoration action would leave the account vulnerable to immediate re-compromise, as existing tokens or cached credentials could still be leveraged.
- ✗
Verify that no other accounts were compromised.
Why it's wrong here
Verifying other accounts for compromise is an important part of scoping the incident, but it does not remediate the specific account that was confirmed as compromised. This action helps identify lateral movement or additional affected identities, yet it leaves the original account's credentials intact and susceptible to continued attacker use. Since the immediate objective is to safely restore the known compromised account, this verification is supplementary rather than a sufficient remediation action.
- ✗
Remove the account from all administrative roles.
Why it's wrong here
Removing the account from administrative roles reduces its privilege level, but it does not invalidate the attacker's possession of the account's valid credentials, meaning they could still authenticate and potentially re-add roles if they retain sufficient rights. This action may limit some immediate blast radius but fails to address the root cause: the identity itself is compromised. A safe restoration requires resetting the password and enforcing MFA to revoke the attacker's access, not just trimming privileges on an account that remains under hostile control.
- ✗
Run a full antivirus scan on the account's devices.
Why it's wrong here
Running a full antivirus scan on the account's devices focuses on endpoint malware and does nothing to invalidate leaked or stolen credentials for the user account. In cases where the compromise originated from a phishing attack or credential stuffing, the attacker may not need any malicious code on a device at all. The account's password remains known to the adversary, so scanning endpoints cannot prevent them from continuing to sign in; the credential must be reset and MFA must be required.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.