SC-200 Respond to security incidents Practice Question
A user reports that they cannot access their Microsoft 365 apps after clicking a link in an email. You suspect token theft. In Microsoft Defender XDR, which incident investigation action should you take first to verify the scope?
⚠ Common exam trap
SC-200 often tests the order of operations in incident response, and candidates who jump to containment (isolate device) before scoping (review sign-in logs) fall into the trap of acting before understanding the incident's breadth.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Review the user's sign-in logs in Microsoft Entra ID for anomalous locations
When token theft is suspected, the first investigative step is to determine scope by reviewing the user's sign-in logs in Microsoft Entra ID for anomalous locations, IPs, or impossible-travel patterns. This confirms whether the token was used from an unexpected location and helps identify other affected accounts before taking containment actions. Verifying scope precedes remediation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Review the user's sign-in logs in Microsoft Entra ID for anomalous locations
Why this is correct
Sign-in logs in Microsoft Entra ID reveal the authentication events tied to the suspected token theft, showing anomalous locations, IP addresses and session details. Reviewing them first establishes which accounts and sessions are affected, defining the incident scope before deeper investigation.
- ✗
Isolate the user's device from the network
Why it's wrong here
Isolation contains the endpoint but reveals nothing about which identities, mailboxes or sessions the stolen token already reached. Device isolation is the right first move for active malware execution or lateral movement, not for scoping token theft across cloud identities.
- ✗
Check the user's device for malware using Microsoft Defender for Endpoint
Why it's wrong here
Scanning the device addresses endpoint malware, yet token theft involves stolen session cookies or refresh tokens usable from any host, so device findings do not establish scope. Endpoint scanning is correct when a compromised device is the suspected initial access vector.
- ✗
Investigate the email in Microsoft Defender for Office 365
Why it's wrong here
Examining the email confirms delivery and payload but not which accounts or sessions the stolen tokens now access, so scope remains unverified. Email investigation is correct when determining phishing reach, sender infrastructure or whether other recipients received the same message.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SC-200
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. You are handling an incident where a user's account was used to access sensitive data from an unusual location. Microsoft Entra ID Identity Protection flagged the sign-in as risky. You need to determine if the account is compromised. Which investigation step should you perform first?
hard- A.Block the user from signing in
- B.Force a password reset for the user
- C.Check if the device used is managed by Intune
- ✓ D.Review the sign-in details and compare with the user's typical behavior
Why D: Before taking any remediation action, you should first review the sign-in details and compare them with the user's typical behavior to determine if the account is actually compromised. This investigation step provides context and helps avoid unnecessary disruptions. Only after confirming a compromise should you proceed with actions like blocking or password reset.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.