Courseiva

SC-200 Respond to security incidents Practice Question

A SOC analyst receives an alert from Microsoft Defender for Cloud Apps indicating that a user downloaded 500 GB of data from SharePoint to an unmanaged device. The user has no history of such behavior. What is the best first step in the incident response process?

⚠ Common exam trap

Watch out — candidates often choose 'Contact the user' (Option B) as a first step, confusing the 'identification' or 'verification' phase with the immediate containment priority required in a potential data exfiltration incident.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Disable the user account in Microsoft Entra ID.

The immediate priority in an incident response process for a potential data exfiltration scenario is to contain the threat. Disabling the user account in Microsoft Entra ID (formerly Azure AD) is the fastest way to revoke access to SharePoint and other cloud resources, preventing further unauthorized data transfer. This aligns with the 'containment' phase of the NIST incident response lifecycle, before any investigation or remediation steps.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Run a full antivirus scan on the unmanaged device.

    Why it's wrong here

    Because the device is unmanaged, you cannot reliably initiate or enforce a full antivirus scan through Microsoft Defender for Endpoint unless it is onboarded; even if a scan could run, it focuses purely on malware presence and does not stop the active, ongoing data exfiltration to the external host. Meanwhile, the scan time gives the attacker a continued window to transfer more data, and any detected malware would not necessarily correlate with the user account compromise triggering the alert.

  • ✗

    Contact the user to verify if the download was intentional.

    Why it's wrong here

    Contacting the user to ask whether the download was intentional effectively tips off a potentially compromised account, because if an attacker is actively using that identity, they will see the outreach and may immediately escalate, destroy evidence, or push through the remaining data before investigators can contain the session. It also relies on the user's self-reporting, which is neither audit-proof nor fast enough, and in a false-positive case it wastes time that should be spent validating the alert through telemetry. This is why identity containment is performed before any user interaction.

  • ✓

    Disable the user account in Microsoft Entra ID.

    Why this is correct

    Disabling the user account in Microsoft Entra ID is the correct immediate containment action because it sets AccountEnabled to false, blocking the compromised identity from authenticating to Microsoft 365 and Defender services that host the data. This action directly interrupts the active download session and prevents the entity from initiating new requests, regardless of whether the device itself is managed, and it does so quickly enough to limit data loss. As a side benefit, it preserves the unmanaged device's source IP and activity logs for later forensic analysis without giving the attacker a warning.

  • ✗

    Create a detection rule for similar behavior in Microsoft Sentinel.

    Why it's wrong here

    Creating a Microsoft Sentinel detection rule for similar behavior is a valuable post-incident hardening step, but it is not a response to the current event: the rule only matches future log events and has no effect on the already-active download or the compromised user's current access. Writing, testing, and deploying a KQL rule can take significant time, during which the attacker continues to exfiltrate data, so it must be deferred until after containment is achieved. In the immediate triage phase, containment actions take priority over detection engineering.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SC-200

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A security analyst receives an alert from Microsoft Defender for Cloud Apps indicating that a user from the finance department downloaded 500 files from SharePoint Online in 10 minutes. The analyst needs to determine if this is a true positive and, if so, contain the incident. Which action should the analyst take first?

medium
  • A.Run a KQL query in Microsoft Sentinel to correlate with other alerts.
  • ✓ B.Suspend the user's account in Microsoft Entra ID.
  • C.Create an alert in Microsoft Sentinel for similar behavior.
  • D.Check the user's risk score in Microsoft Entra ID Identity Protection.

Why B: When a user downloads a large number of files in a short period from SharePoint Online, it may indicate a data exfiltration attempt. The first action should be to contain the incident by suspending the user's account in Microsoft Entra ID to prevent further access. This is an immediate containment step before investigating further. Checking the user's risk score (D) or creating alerts (C) are secondary steps. Correlating with other alerts (A) can be done but containment takes priority.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.