SC-200 Respond to security incidents Practice Question
During an incident, an analyst finds that a user's account was compromised and used to send spam. The analyst needs to revoke all active sessions for that user. What should the analyst do?
⚠ Common exam trap
SC-200 often tests the misconception that resetting a password immediately logs out an attacker — candidates must recognize that token revocation is the only action that invalidates existing sessions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Revoke the user's sessions in Microsoft Entra ID.
Revoking sessions in Microsoft Entra ID immediately invalidates all refresh tokens and active sign-in sessions for the compromised user, cutting off the attacker's access without disrupting the account's ability to be re-secured. This is the targeted response for session hijacking because it terminates existing tokens rather than just changing credentials. Password reset alone does not invalidate already-issued tokens, so the attacker could remain authenticated.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Reset the user's password.
Why it's wrong here
A password reset does not invalidate existing refresh tokens, so already-issued sessions remain usable until expiry. It tempts because it is a standard compromise response, but revoking all active sessions requires the dedicated Revoke sessions action in Microsoft Entra ID, not a credential change.
- ✓
Revoke the user's sessions in Microsoft Entra ID.
Why this is correct
Revoking sessions in Microsoft Entra ID invalidates all refresh tokens and active sessions for the compromised account, immediately cutting off the attacker's access while the password is reset. This directly satisfies the requirement to revoke all active sessions.
- ✗
Create a Conditional Access policy to block the user.
Why it's wrong here
A Conditional Access block policy prevents new authentications but does not terminate tokens already issued, so active sessions continue. It tempts because it restricts access, yet the requirement is immediate session revocation, which the Revoke sessions action in Microsoft Entra ID performs directly.
- ✗
Disable the user account in Microsoft Entra ID.
Why it's wrong here
Disabling the account blocks new sign-ins but leaves existing refresh tokens and sessions valid, so the attacker's active sessions persist. It tempts as a containment step, yet revoking sessions specifically requires the Revoke sessions action in Microsoft Entra ID, which invalidates tokens immediately.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on SC-200
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. You are investigating a security incident involving a compromised user account. The attacker used the account to access sensitive data in SharePoint Online. Which TWO actions should you take to remediate the incident? (Choose two.)
easy- A.Reset the user's password.
- ✓ B.Revoke all refresh tokens for the user.
- ✓ C.Disable the user account in Microsoft Entra ID.
- D.Review the sign-in logs to determine the extent of the breach.
- E.Create a Conditional Access policy to require MFA for the user.
Why B: Option B is correct because revoking all refresh tokens for the compromised user immediately invalidates the OAuth 2.0 refresh tokens that the attacker could use to silently obtain new access tokens for SharePoint Online and other Microsoft 365 resources, cutting off their persistent access. Option C is correct because disabling the user account in Microsoft Entra ID blocks any further authentication attempts with that identity, preventing the attacker from signing in again while the incident is contained. Option A is not the best remediation action here because resetting the password alone does not invalidate existing refresh tokens, so the attacker could retain access until those tokens expire. Option D is a detection/investigation step rather than a remediation action, and Option E is a preventive control that does not immediately stop an active compromise.
Variation 2. You are responding to an incident where a user's Microsoft Entra ID account was compromised and used to send phishing emails internally. You need to prevent further damage. Which two actions should you take first?
hard- A.Reset the user's password
- ✓ B.Revoke the user's sessions
- ✓ C.Disable the user account in Microsoft Entra ID
- D.Block all external email from the organization
- E.Remove the user from all distribution groups
Why B: The two correct first-response actions are B, revoke the user's sessions, and C, disable the user account in Microsoft Entra ID. Disabling the account immediately stops any further sign-ins and blocks the attacker from using the compromised identity, while revoking sessions invalidates existing refresh tokens and access tokens so any already-authenticated sessions (including those used to send phishing email) are terminated. Together these contain the incident quickly without waiting on password changes or mailbox cleanup. Option A (reset password) is useful but alone does not kill active sessions, and it is not the fastest containment step. Option D (block all external email) is overly broad and unrelated to the compromised account, and option E (remove from distribution groups) is a remediation detail, not an immediate containment action.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.