Courseiva

SC-200 Respond to security incidents Practice Question

An analyst in your SOC receives a Microsoft Defender for Cloud Apps alert indicating a suspicious Power Automate flow that is forwarding emails to an external domain. The analyst needs to disable the flow immediately. Which action should they take?

⚠ Common exam trap

SC-200 often tests whether candidates choose the most targeted remediation action available in the alerting tool rather than broader, slower controls like blocking domains or disabling accounts.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use the governance action in Microsoft Defender for Cloud Apps to disable the flow

Microsoft Defender for Cloud Apps (MDCA) provides governance actions directly on discovered app activities, including the ability to disable a Power Automate flow from within the alert. This is the fastest, most targeted remediation because it acts on the specific flow rather than broader controls.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Block the external domain in Exchange Online mail flow rules

    Why it's wrong here

    Mail flow rules act on messages in transit, not on the Power Automate connector that sends them, so the flow keeps forwarding. Exchange transport rules would be the right control for blocking mail from a domain when the sender is a normal mailbox, not an automated flow.

  • ✗

    Remove the flow from the Microsoft 365 admin center

    Why it's wrong here

    The Microsoft 365 admin centre does not expose Power Automate flows for removal; they are managed in the Power Platform admin centre or via Defender for Cloud Apps governance actions. Admin centre removal applies to mailbox or licence objects, which is the correct scope for those resources, not flows.

  • ✗

    Disable the user account in Microsoft Entra ID

    Why it's wrong here

    Disabling the user stops interactive sign-in but the flow's connections may still run under its own service principal or stored credentials, so forwarding continues. Account disablement is correct for containing a compromised human identity, not for stopping a specific automated flow.

  • ✓

    Use the governance action in Microsoft Defender for Cloud Apps to disable the flow

    Why this is correct

    Microsoft Defender for Cloud Apps governance actions apply remediation directly to connected apps, letting the analyst disable the offending Power Automate flow from within the alert. This stops the exfiltration immediately without leaving the portal, matching the requirement to disable the flow at once.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.