SC-200 Respond to security incidents Practice Question
Which TWO actions are valid containment steps for a compromised user account in Microsoft Defender XDR?
⚠ Common exam trap
Candidates often confuse remediation steps (like running an antivirus scan) with containment steps, or they mistakenly think that adding a user to a privileged role could help monitor the account, when in fact it escalates the compromise.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Disable the user account in Microsoft Entra ID
Disabling the user account in Microsoft Entra ID is a valid containment step because it immediately revokes the user's access to all cloud resources, including Microsoft 365, Azure, and any applications relying on Entra ID authentication. This prevents the compromised account from being used for further malicious activities while preserving the account for investigation. It is a core incident response action in Microsoft Defender XDR for containing identity-based threats.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a new email rule to forward emails
Why it's wrong here
Creating an email forwarding rule on the compromised mailbox is not a containment action because it does not restrict or sever the attacker's existing access; instead, it may actually facilitate data exfiltration by automatically sending sensitive emails to an external address. Since an attacker could use such a rule to maintain visibility or steal information, it runs contrary to the goal of isolating the incident. Proper containment would involve revoking credentials and blocking sign-ins, not modifying mailbox behavior.
- ✓
Disable the user account in Microsoft Entra ID
Why this is correct
Disabling the user account in Microsoft Entra ID is a valid containment step because it immediately prevents any further authentication attempts using that identity, cutting off the attacker's current access path to cloud applications, Microsoft 365, and other Entra ID-integrated resources. This reversible, non-destructive action preserves all user data and activity logs for forensic analysis while stopping ongoing malicious activity. It is one of the first actions an incident responder should take when a user identity is known to be compromised.
- ✗
Add the user to a privileged role
Why it's wrong here
Adding the user to a privileged role is the opposite of containment, as it escalates the account's permissions and expands the attacker's reach into the environment. Granting roles such as Global Administrator or Privileged Role Administrator would give the attacker additional control over tenant settings, potentially enabling persistence mechanisms like backdoor accounts or modified policies. This action would increase the blast radius and should never be taken during a containment phase.
- ✓
Reset the user's password
Why this is correct
Resetting the user's password invalidates the attacker's stolen credentials and forces the legitimate user to authenticate with a new secret, making it a direct containment measure for credential-compromise incidents. However, it is important to understand that password reset alone may not terminate existing sessions or revoke tokens, so it should be paired with Entra ID's "Revoke sessions" feature or equivalent to fully contain the attack. Nevertheless, it removes the immediate authentication vector the attacker is likely using.
- ✗
Run a full antivirus scan on the user's device
Why it's wrong here
Running a full antivirus scan on the user's device is a remediation or eradication step, not a containment action, because it attempts to clean a compromised host rather than isolate the compromised identity or stop access to cloud resources. Even if malware is detected and removed, the attacker could still retain valid credentials, session tokens, or other footholds, allowing continued access. Containment should first focus on breaking the attacker's authentication and access paths, such as disabling the account or resetting credentials, before scanning for malware.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.