SC-200 Respond to security incidents Practice Question
During an incident response, a security analyst identifies that a user's account was used to access sensitive data from an anomalous location. The analyst needs to immediately prevent further access from that account while preserving forensic data. Which action should the analyst take?
⚠ Common exam trap
Many candidates confuse 'revoke sessions' (which only ends current sessions but allows re-authentication) with 'disable account' (which permanently blocks all access), leading them to choose Option A as a quick fix without understanding that it does not prevent further access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Disable the user account in Microsoft Entra ID.
Disabling the user account in Microsoft Entra ID immediately prevents any further authentication or access to resources, including sensitive data, while preserving the account's forensic data (e.g., sign-in logs, audit events) for investigation. This action stops all current and future sessions without deleting the account or its associated data, which is critical for incident response.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Revoke the user's current sessions in Microsoft Entra ID.
Why it's wrong here
Revoking current sessions only invalidates the user's active tokens and cookies in Entra ID, but it leaves the underlying compromised credentials intact. Because the attacker can simply authenticate again with the known username and password, a fresh session can be established immediately. This makes session revocation a temporary mitigation, not a containment step, and it should be paired with disabling the account or resetting the credentials.
- ✗
Block the IP address of the anomalous location in the firewall.
Why it's wrong here
Blocking the observed IP address in a firewall treats a symptom rather than the source of the compromise, because the actor often uses VPNs, proxied egress points, or distributed residential IPs. Even if this single address is denied, the attacker can continue authenticating from other locations, since the user account itself remains enabled and functional. It also risks blocking legitimate access if the user happens to be traveling and matches the anomalous location.
- ✓
Disable the user account in Microsoft Entra ID.
Why this is correct
Disabling the user account in Microsoft Entra ID is the correct containment action because it immediately prevents any new authentication attempts, including interactive and behind-the-scenes service account sign-ins. The user object, its assigned licenses, group memberships, and mailbox data are all preserved, so forensic analysis can continue without further compromise. This provides an unambiguous, identity-based kill switch that overrides every other access path relying on the user's credentials.
- ✗
Enable multi-factor authentication (MFA) for the user.
Why it's wrong here
Enabling MFA does not terminate the attacker's existing authenticated access, because the current session tokens and cookies were already issued and remain valid until they expire. MFA only creates a new challenge for future sign-in attempts, so the compromised account stays enabled and the adversary can keep operating inside the current session. It is a strong preventive security control, but it is the wrong tool for stopping an active incident.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.