SC-200 Respond to security incidents Practice Question
A security analyst receives an alert from Microsoft Defender for Identity about a suspicious Kerberos ticket request. What is the first step the analyst should take?
⚠ Common exam trap
The trap here is that candidates often jump to containment (disable account) or remediation (reset password) without first validating the alert, confusing the 'respond' phase with the initial 'validate' step required by incident response best practices.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Validate the alert by checking the user's recent activity
When Microsoft Defender for Identity alerts on a suspicious Kerberos ticket request, the first step is to validate the alert by checking the user's recent activity. This ensures the alert is not a false positive caused by legitimate behavior (e.g., scheduled tasks or application service tickets) before taking any disruptive action. Defender for Identity uses network traffic and event logs to detect anomalies like overpass-the-hash or Kerberoasting, but initial validation prevents unnecessary account lockouts or password resets.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disable the user account
Why it's wrong here
Disabling the account is an invasive containment action that can instantly lock out a legitimate user, potentially disrupting business operations and causing a denial of service. In Microsoft Defender, alerts frequently require triage because they may be false positives, so you must first validate the alert by examining the user's recent activity and sign-in logs before applying account-level restrictions. Prematurely disabling a user account without evidence of compromise violates the verified-response principle and could trigger unnecessary IT helpdesk escalations.
- ✗
Reset the user's password
Why it's wrong here
Resetting the user's password is a credential-remediation step that assumes the account has been compromised; however, in this scenario you have not yet confirmed the alert's validity. In Microsoft Defender, a password reset is often a post-validation action taken only after you have reviewed the user's recent activity, such as anomalous sign-ins, impossible travel, or suspicious mailbox rules, to determine that the account was truly breached. Resetting too early can destroy forensic evidence, especially if the attacker changed the password, and it may cause unnecessary user friction if the alert is a false positive.
- ✗
Run a full antivirus scan on the user's device
Why it's wrong here
Running a full antivirus scan on the user's device is not directly relevant because this alert appears to be user- or identity-centric rather than endpoint-based, and the malicious activity could originate from a cloud app or an attacker using stolen credentials. In Microsoft Defender, alerts from identity signals do not indicate a local malware infection, so scanning the endpoint will not investigate the root cause. The proper triage step is to check the user's recent activity to confirm whether the alert corresponds to genuine risky behavior, and a scan would only delay that analysis.
- ✓
Validate the alert by checking the user's recent activity
Why this is correct
Validating the alert by checking the user's recent activity is the correct first step because it confirms whether the alert corresponds to a genuine security event, such as anomalous sign-ins, impossible travel, or suspicious mailbox activity in Microsoft Defender. By reviewing the user's sign-in logs and other evidence, you can determine the alert's true positive or false positive status, which guides all subsequent containment and remediation decisions. This triage approach aligns with incident response best practices, ensuring you act based on evidence rather than assumptions and avoiding unnecessary disruption to the user.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.