SC-200 Respond to security incidents Practice Question
An incident is opened in Microsoft Sentinel for multiple sign-in failures from a single IP address targeting a privileged user account. Which action is most effective in automatically responding to this incident?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a playbook to block the IP address in the firewall.
The most effective automated response is to block the IP address in the firewall via a playbook, as it directly stops the attack source. Disabling the user account is too broad and may affect legitimate access. Enabling MFA does not stop the current attack. Reporting the IP is not immediate.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create a playbook to block the IP address in the firewall.
Why this is correct
Creating a playbook that invokes a firewall API (via Azure Logic Apps) to block the offending IP is a direct containment action. It severs the attacker's communication path to your environment at the network boundary, without affecting the legitimate user's ability to sign in. This is the immediate, low-disruption response that stops the ongoing brute-force attempts from that source.
- ✗
Enable conditional access policy to require MFA for the user.
Why it's wrong here
Conditional access requiring MFA changes authentication requirements for future sign-ins; it neither blocks the source IP nor triggers automatically from the Sentinel incident. It is tempting because MFA enrolment hardens the privileged account, and would be correct as a standing access control rather than an automated incident response action.
- ✗
Create a playbook to automatically disable the user account.
Why it's wrong here
Disabling the user account through an automated playbook blocks all authentication for that user, including legitimate access, and could cause a denial of service if the account is not actually compromised. It also fails to stop the attacker if they are using a different identity, and it does not act on the source IP, which is the true indicator of the attack. This is a blunt, high-impact action better reserved for confirmed account compromise rather than an initial containment step for multiple failed sign-ins.
- ✗
Report the IP address to Microsoft for threat intelligence.
Why it's wrong here
Submitting the IP address to Microsoft for threat intelligence enriches global detection and contributes to future security research, but it is not a real-time containment measure. The IP may only be added to shared blocklists after manual or automated review, leaving your environment exposed during the attack. In an active incident, you need an automated, immediate action such as a firewall block to stop the communication, not an asynchronous reporting step that has no direct benefit to this specific incident.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.