Courseiva

SC-200 Respond to security incidents Practice Question

An incident in Microsoft Sentinel involves multiple alerts indicating a potential data exfiltration via SharePoint Online. You need to respond and remediate. Which THREE actions should be taken?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Remove external sharing permissions on SharePoint sites.

Removing external sharing permissions on SharePoint sites (A) prevents further data leaks via sharing. Blocking the user account in Microsoft Entra ID (B) stops further access immediately. Isolating the user's device using Microsoft Defender for Endpoint (D) contains the threat by preventing lateral movement. Resetting the user's password and enforcing MFA (C) is a good follow-up but less immediate than blocking the account. Creating a custom detection rule (E) is proactive but not a direct response to the current incident.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Remove external sharing permissions on SharePoint sites.

    Why this is correct

    In the context of a Sentinel incident, external sharing on SharePoint sites is a common data exfiltration vector when accounts are compromised. Removing external sharing permissions—via the SharePoint admin center or PowerShell cmdlets like Set-SPOTenant -SharingCapability—immediately revokes external users' ability to access shared links, cutting off the attacker's current path to exfiltrate data. This is a direct containment action at the data plane, and it is crucial to perform before or alongside user-level blocking to stop exfiltration that has already been enabled.

  • ✓

    Block the user account in Microsoft Entra ID.

    Why this is correct

    Blocking the user account in Microsoft Entra ID—using the 'Block sign-in' setting or Revoke-MgUserSignInSession—is an immediate control-plane containment that prevents the compromised principal from authenticating to any Microsoft 365 resource. This is faster and more comprehensive than a password reset because it doesn't rely on the user performing an action, and it invalidates the attacker's ability to use stolen credentials for new token requests. Existing active sessions may persist until token expiry, so combine with session revocation for full effect, but sign-in blocking remains the first and most decisive move.

  • ✗

    Reset the user's password and enforce MFA.

    Why it's wrong here

    Resetting the user's password and enforcing MFA is a good post-incident recovery action, but it is not the most immediate containment step. A password reset alone does not invalidate existing refresh tokens or access sessions, and the attacker may have already registered their own MFA device or created persistence mechanisms like OAuth grants. MFA enforcement can take time to propagate across services and requires user coordination, whereas blocking the account or isolating the device stops activity instantly. In an active incident, this option is therefore correct only as a follow-up, not as the primary response.

  • ✓

    Isolate the user's device using Microsoft Defender for Endpoint.

    Why this is correct

    Isolating the user's device with Microsoft Defender for Endpoint—via the 'Isolate device' action—severs all network communication from that endpoint to external hosts, except for the Defender service itself. This is a strong containment measure when the incident involves a compromised device performing data exfiltration or lateral movement. However, it only covers the endpoint; it does not affect cloud-resident data like SharePoint external sharing links, so it must be paired with cloud-level containment (e.g., blocking the user and removing shared permissions) to fully stop the leak.

  • ✗

    Create a custom detection rule for similar activity.

    Why it's wrong here

    Creating a custom detection rule for similar activity is a valuable step after an incident, but it is not an immediate containment action. Writing and deploying a Sentinel analytics rule does not stop the current attacker's active access or reduce the blast radius; it only helps detect future recurrences. Immediate response should prioritize blocking the user, isolating the device, and revoking sharing permissions. This option belongs in the post-incident review phase, so it is incorrect as an immediate response.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.