Courseiva

SC-200 Respond to security incidents Practice Question

A SOC analyst receives a Microsoft Defender for Cloud Apps alert about a mass download of files from a SharePoint site by a single user. The analyst needs to contain the incident. Which action should be taken first?

⚠ Common exam trap

Test-takers frequently confuse containment with investigation or remediation, picking a post-incident step like malware scanning instead of the immediate account disablement action that stops the active threat.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Suspend the user account in Microsoft Entra ID.

Suspending the user account in Microsoft Entra ID immediately revokes all access tokens and prevents further authentication, stopping the mass download in progress. This is the fastest containment action because it disables the user's ability to access any Microsoft 365 resource, including SharePoint, without waiting for other processes like scanning or notifications.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Increase the SharePoint download limit.

    Why it's wrong here

    Increasing the SharePoint download limit is counterproductive because this alert is triggered by an anomaly detection policy that flags excessive or unusual download activity. Raising that threshold would simply allow the user to continue exfiltrating more files before any further detection occurs, leaving the threat active and doing nothing to remediate the current incident.

  • ✗

    Notify the user's manager.

    Why it's wrong here

    Notifying the user's manager is a passive communication step that does not contain, stop, or investigate the active suspicious activity. The manager has no immediate technical ability to revoke access or halt ongoing downloads, and the alert will remain unresolved in the meantime. Notification should occur only after the account has been contained or disabled.

  • ✓

    Suspend the user account in Microsoft Entra ID.

    Why this is correct

    Suspending the user account in Microsoft Entra ID is the correct immediate containment action because it revokes the user's ability to sign in and access SharePoint, stopping all further downloads at once. Defender for Cloud Apps can trigger this governance action natively, integrating with Entra ID to disable the account. This aligns with incident response best practices, prioritizing containment of a likely data exfiltration before investigation.

  • ✗

    Run a malware scan on the downloaded files.

    Why it's wrong here

    Running a malware scan on downloaded files is inappropriate for this alert because suspicious download behavior is not synonymous with malware infection. Even if the files were clean, the scan would not prevent the user from continuing to download additional data, leaving the exfiltration channel open. It addresses an unrelated hypothesis while ignoring the immediate need to stop access.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.