Courseiva

SC-200 Respond to security incidents Practice Question

A security analyst detects a suspicious login from an unusual location for a user in Microsoft Defender XDR. The analyst needs to investigate and contain the incident. Which TWO actions should be taken?

⚠ Common exam trap

The trap is choosing password reset as containment — candidates assume resetting credentials stops the attacker, but without disabling the account or revoking sessions, an attacker with a valid token or persistence mechanism retains access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Disable the user account from Microsoft Entra ID.

Option A is correct because disabling the user account in Microsoft Entra ID immediately blocks the compromised identity from authenticating, which is the fastest containment action to stop further unauthorized access during a suspicious-login incident. Option C is correct because reviewing the user's sign-in logs and Identity Protection risk level in Microsoft Entra ID provides the investigative context — source IP, location, device, and whether the sign-in was flagged as risky — needed to confirm compromise before or alongside containment. Option B is not the right primary action because advanced hunting is a proactive threat-hunting tool, not the standard investigative/containment step for a specific flagged sign-in. Option D is not appropriate here because automated investigation playbooks are triggered by specific alerts or incidents and are not the analyst's direct manual containment action. Option E is not the best choice because a password reset alone does not immediately terminate active sessions or block the account, so it is weaker containment than disabling the account.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Disable the user account from Microsoft Entra ID.

    Why this is correct

    Disabling the account in Microsoft Entra ID immediately blocks further authentication and token issuance for the compromised identity, containing the incident while investigation continues. This directly satisfies the stem's requirement to contain a suspicious sign-in from an unusual location.

  • ✗

    Create a custom hunting query in Microsoft 365 Defender advanced hunting.

    Why it's wrong here

    Advanced hunting queries only search log data; they cannot contain or remediate an active incident. It is tempting because hunting is genuinely useful for proactively locating related suspicious activity across your estate, but the stem demands containment, which requires response actions such as disabling the account or revoking sessions.

  • ✓

    Review the user's sign-in logs and risk level in Microsoft Entra ID Identity Protection.

    Why this is correct

    Reviewing sign-in logs and risk level in Microsoft Entra ID Identity Protection surfaces the anomalous location, device and conditional access outcome behind the alert, confirming whether credentials are compromised. This satisfies the investigation requirement by correlating Defender XDR incident data with Entra ID risk detections before containment actions are applied.

  • ✗

    Run an automated investigation playbook.

    Why it's wrong here

    An automated investigation playbook responds and remediates, but does not itself establish the scope of the suspicious sign-in. It is tempting because automation accelerates containment, and would be correct once triage confirms a genuine compromise, but investigation must precede automated response.

  • ✗

    Reset the user's password.

    Why it's wrong here

    A password reset does not terminate the attacker's existing authenticated sessions or tokens, so the suspicious access continues. It is tempting because credential compromise is a common cause of anomalous sign-ins, yet the immediate containment step is revoking sessions and disabling the account, not merely changing the password.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on SC-200

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A security analyst detects a suspicious sign-in from an unusual location using Microsoft Entra ID. The user has not enabled MFA. Which action should the analyst take first to investigate and potentially contain the incident?

medium
  • A.Reset the user's password immediately.
  • B.Enable Conditional Access to block all sign-ins from that location.
  • ✓ C.Disable the user account.
  • D.Block legacy authentication for the entire tenant.

Why C: When a suspicious sign-in is detected and the user has not enabled MFA, the first containment action should be to disable the user account to prevent further unauthorized access. This immediately blocks the attacker while allowing investigation to continue. Other actions like password reset or Conditional Access may be part of remediation but are not the first step.

Variation 2. During an incident response, a security analyst identifies that a user's account was used to access sensitive data from an anomalous location. The analyst needs to immediately prevent further access from that account while preserving forensic data. Which action should the analyst take?

medium
  • A.Revoke the user's current sessions in Microsoft Entra ID.
  • B.Block the IP address of the anomalous location in the firewall.
  • ✓ C.Disable the user account in Microsoft Entra ID.
  • D.Enable multi-factor authentication (MFA) for the user.

Why C: Disabling the user account in Microsoft Entra ID immediately prevents any further authentication or access to resources, including sensitive data, while preserving the account's forensic data (e.g., sign-in logs, audit events) for investigation. This action stops all current and future sessions without deleting the account or its associated data, which is critical for incident response.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.