Courseiva
Respond to security incidentshardMultiple SelectObjective-mapped

SC-200 Respond to security incidents Practice Question

Which THREE steps are part of the containment phase of incident response in Microsoft Sentinel? (Select THREE.)

⚠ Common exam trap

A common mix-up: candidates confuse containment actions (stopping the attack) with investigation (collecting evidence) or recovery (restoring data), leading candidates to select forensic collection or backup restoration as containment steps.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Disable compromised user accounts in Microsoft Entra ID.

Disabling compromised user accounts in Microsoft Entra ID is a containment step because it immediately revokes the account's access tokens and prevents further authentication, stopping an attacker from using that identity to move laterally or access resources. This aligns with the containment phase's goal of limiting the blast radius of an incident.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Disable compromised user accounts in Microsoft Entra ID.

    Why this is correct

    Disabling accounts stops further misuse.

  • Isolate affected devices using Microsoft Defender for Endpoint.

    Why this is correct

    Isolation is a containment action.

  • Collect forensic data from affected endpoints.

    Why it's wrong here

    Forensics is investigation, not containment.

  • Block malicious IP addresses and domains in Microsoft Defender for Cloud Apps.

    Why this is correct

    Blocking indicators contains the attack.

  • Restore encrypted files from backup.

    Why it's wrong here

    Restoration is recovery.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1XEAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

Courseiva writes every SC-200 question from scratch — 209 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.