SC-200 Manage a security operations environment Practice Question
A SOC analyst suspects a user account is compromised based on anomalous sign-in activity detected by Microsoft Entra ID Protection. The analyst needs to confirm and contain the threat. What is the first action the analyst should take?
⚠ Common exam trap
The trap here is that candidates often jump to containment actions like resetting passwords or disabling accounts, but the SC-200 exam emphasizes the 'investigate before remediate' principle, where reviewing risk detections and sign-in logs in Entra ID Protection is the mandatory first step to confirm the threat.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Review the user's risk level and sign-in logs in Microsoft Entra ID Protection
The first step when investigating a potential account compromise is to review the user's risk level and sign-in logs in Microsoft Entra ID Protection. This allows the analyst to confirm the threat by examining risk detections, sign-in patterns, and contextual details before taking any containment actions. Prematurely resetting passwords or disabling accounts could disrupt legitimate user activity or alert the attacker without a full understanding of the scope.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Reset the user's password immediately
Why it's wrong here
Resetting the user's password immediately is premature without evidence, as it may lock out the legitimate user and does not terminate an attacker's existing access tokens or sessions. The first step should be to validate the compromise using Entra ID Protection's risk signals and sign-in logs before taking disruptive remediation actions.
- ✓
Review the user's risk level and sign-in logs in Microsoft Entra ID Protection
Why this is correct
Reviewing the user's risk level and sign-in logs in Microsoft Entra ID Protection is the correct initial action because it provides aggregated risk detections and contextual details, such as impossible travel or unfamiliar sign-in properties, to confirm whether a compromise has actually occurred. This investigation-first approach enables you to make an informed decision about whether to require a password reset, revoke sessions, or take other containment steps.
- ✗
Disable the user account in Microsoft Entra ID
Why it's wrong here
Disabling the user account in Microsoft Entra ID before confirming compromise can cause unnecessary outage for a potentially legitimate user and may alert the attacker if the account is indeed compromised, giving them time to pivot. A measured response requires first reviewing Entra ID Protection's risk reports and sign-in logs to establish a factual basis, after which account disabling becomes a justified containment action.
- ✗
Block the user's sign-in from all locations
Why it's wrong here
Blocking the user's sign-in from all locations is an overly broad and premature containment step, as it does not differentiate between malicious and benign sign-in attempts and can prevent the user from accessing legitimate resources while the investigation is ongoing. It should only be considered after Entra ID Protection confirms the compromise and you have analyzed the specific sign-in patterns, otherwise you risk both operational disruption and missing the actual attack vector.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.