SC-200 Respond to security incidents Practice Question
An analyst in your SOC receives a Microsoft Defender for Cloud Apps alert indicating a suspicious Power Automate flow that is forwarding emails to an external domain. The analyst needs to disable the flow immediately. Which action should they take?
⚠ Common exam trap
SC-200 often tests whether candidates choose the most targeted remediation action available in the alerting tool rather than broader, slower controls like blocking domains or disabling accounts.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use the governance action in Microsoft Defender for Cloud Apps to disable the flow
Microsoft Defender for Cloud Apps (MDCA) provides governance actions directly on discovered app activities, including the ability to disable a Power Automate flow from within the alert. This is the fastest, most targeted remediation because it acts on the specific flow rather than broader controls.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Block the external domain in Exchange Online mail flow rules
Why it's wrong here
Mail flow rules act on messages in transit, not on the Power Automate connector that sends them, so the flow keeps forwarding. Exchange transport rules would be the right control for blocking mail from a domain when the sender is a normal mailbox, not an automated flow.
- ✗
Remove the flow from the Microsoft 365 admin center
Why it's wrong here
The Microsoft 365 admin centre does not expose Power Automate flows for removal; they are managed in the Power Platform admin centre or via Defender for Cloud Apps governance actions. Admin centre removal applies to mailbox or licence objects, which is the correct scope for those resources, not flows.
- ✗
Disable the user account in Microsoft Entra ID
Why it's wrong here
Disabling the user stops interactive sign-in but the flow's connections may still run under its own service principal or stored credentials, so forwarding continues. Account disablement is correct for containing a compromised human identity, not for stopping a specific automated flow.
- ✓
Use the governance action in Microsoft Defender for Cloud Apps to disable the flow
Why this is correct
Microsoft Defender for Cloud Apps governance actions apply remediation directly to connected apps, letting the analyst disable the offending Power Automate flow from within the alert. This stops the exfiltration immediately without leaving the portal, matching the requirement to disable the flow at once.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.