Courseiva

SC-200 Respond to security incidents Practice Question

During a security incident, a Microsoft Sentinel analytics rule generated an alert for a suspicious sign-in from an unusual location. The incident involves a user whose account has been compromised. The security team needs to take immediate actions to remediate and prevent further damage. Which THREE actions should the security team prioritize?

⚠ Common exam trap

Test-takers frequently confuse detection actions (like raising risk level) with containment actions, or mistakenly think reviewing all audit logs is a priority step when the focus should be on immediate remediation of the compromised account.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Reset the user's password

Resetting the user's password (A) is a critical immediate step because it invalidates the current compromised credentials, preventing the attacker from using the known password to authenticate again. In Microsoft Entra ID, a password reset forces the user to create a new credential, which the attacker does not possess, effectively cutting off one of the most common attack vectors.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Reset the user's password

    Why this is correct

    Resetting the user's password in Microsoft Entra ID is a direct containment action because it invalidates the previously valid credential. If the attacker gained access via a phished or stolen password, this immediately prevents them from using that secret for interactive sign-in. It is a focused remediation step that should be performed as soon as the user is confirmed as a legitimate account holder, forcing them to create a new password on next sign-in.

  • ✓

    Revoke the user's session tokens

    Why this is correct

    Revoking the user's session tokens via Microsoft Graph (for example, the revokeSignInSessions operation) invalidates all refresh and access tokens issued to applications for that user. Password reset alone does not kill tokens that the attacker may already have captured, so the attacker can continue reaching mail and files. This action terminates active sessions and forces clients to re-authenticate, closing the token-based persistence path.

  • ✗

    Review audit logs for all users

    Why it's wrong here

    Reviewing audit logs for all users is a forensic and scoping activity, not an immediate isolation control. It helps determine the blast radius, identify indicators of compromise, and reconstruct the attack timeline, but it does not prevent an active attacker from continuing to use the compromised account. In an active incident, containment actions must be executed first; log review should run in parallel or afterward, not replace remediation.

  • ✗

    Raise the user's risk level in Identity Protection

    Why it's wrong here

    Manually raising a user's risk level in Identity Protection is not a remediation control; it only changes a risk classification value. This value may influence Conditional Access policies only if such policies are already configured to block or require step-up authentication on high risk, and the risk calculation is meant to be based on real detected signals. Because it neither revokes credentials nor invalidates sessions, it has no immediate impact on the attacker's current access and is therefore not a containment action.

  • ✓

    Disable the user account in Microsoft Entra ID

    Why this is correct

    Disabling the user account in Microsoft Entra ID blocks all future authentication attempts by setting the accountEnabled attribute to false. This stops the attacker from signing in using the stolen password or from acquiring new tokens. It is more disruptive than a password reset because the legitimate user cannot access any resource until an administrator re-enables the account, so it should be chosen when the account is believed to be fully compromised.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.