Courseiva

SC-200 Respond to security incidents Practice Question

A security analyst receives a Microsoft Defender for Cloud Apps alert about a suspicious sign-in from an IP address in a sanctioned app. The analyst needs to immediately prevent further access from that IP. What should the analyst do?

⚠ Common exam trap

Many candidates confuse the scope of Conditional Access in Entra ID (which is a broader identity-level control) with the app-specific, session-level control provided by Defender for Cloud Apps access policies, leading them to choose Option B instead of C.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an IP address-based access policy in Microsoft Defender for Cloud Apps.

Microsoft Defender for Cloud Apps provides native IP address-based access policies that can immediately block traffic from a specific IP address for a sanctioned app. This action is taken directly within Defender for Cloud Apps, without needing to modify Entra ID Conditional Access policies, and it applies in real time to the app session. The analyst can create a policy that blocks access from the suspicious IP, preventing further sign-ins from that address.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a mailbox rule to delete emails from that IP.

    Why it's wrong here

    A mailbox rule operates on email messages in Exchange Online, filtering or deleting items based on sender, subject, or other mail properties. The Defender for Cloud Apps alert about a suspicious IP concerns user sign-in and cloud app access, not email flow. Deleting emails from that IP would not prevent the IP from accessing cloud apps or revoke any existing sessions.

  • ✗

    Create a Conditional Access policy in Microsoft Entra ID to block the IP.

    Why it's wrong here

    Conditional Access policies in Microsoft Entra ID can block IPs, but this Defender for Cloud Apps alert offers a direct remediation to create an IP-based access policy within Cloud Apps itself. While a Conditional Access policy could achieve similar control, it is not the immediate action provided by the alert and requires separate policy configuration. Additionally, Cloud Apps policies can be scoped to specific apps and integrate seamlessly with the alert context.

  • ✓

    Create an IP address-based access policy in Microsoft Defender for Cloud Apps.

    Why this is correct

    From the Defender for Cloud Apps alert, you can create an IP address-based access policy that blocks the suspicious IP from all or selected cloud apps. This policy is enforced via the Cloud Apps conditional access proxy, providing real-time control over user access. It is the recommended, alert-specific remediation because it directly addresses the source IP identified in the threat, preventing further malicious activity.

  • ✗

    Reset the user's password and require MFA re-registration.

    Why it's wrong here

    Resetting the user's password and requiring MFA re-registration addresses potential credential compromise but does not block the specific IP address flagged in the alert. Even if the password is changed, an attacker could still use valid sessions or other credentials from that IP to access apps. The immediate need is to restrict access from the malicious IP, which is only achieved through an access policy, not a password reset.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.