Courseiva

SC-200 Respond to security incidents Practice Question

Which TWO actions should be taken immediately when a compromised user account is detected in Microsoft Entra ID?

⚠ Common exam trap

A common mix-up: candidates choose 'Reset the user's password' as the first action, overlooking that existing sessions remain valid until tokens expire, so session revocation must precede password reset to fully contain the compromise.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Revoke all current sessions.

Revoking all current sessions (Option A) is a critical immediate action because it terminates all active authentication tokens and sessions for the compromised account, preventing the attacker from continuing to use existing tokens to access resources. This action leverages Microsoft Entra ID's token revocation capabilities, which invalidate refresh tokens and access tokens issued before the revocation, effectively cutting off the attacker's current access without waiting for password changes or other mitigations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Revoke all current sessions.

    Why this is correct

    Revoking all current sessions immediately invalidates the access tokens, refresh tokens, and session cookies that have already been issued to the user, terminating any active attacker foothold in real time. This is a containment-first action because it stops ongoing malicious activity without waiting for password changes or conditional access checks. However, it only disrupts existing authentications; it does not prevent future sign-ins, so it must be paired with disabling the account to block new authentication attempts.

  • ✗

    Notify the user's manager.

    Why it's wrong here

    Notifying the user's manager is a communication and escalation step, not a technical containment measure. It has no effect on the attacker's ability to continue using the compromised account because it does not revoke tokens, terminate sessions, or alter authentication policies. This should be done after immediate containment actions are in place, as the priority is to stop the breach before informing stakeholders.

  • ✓

    Disable the user account.

    Why this is correct

    Disabling the user account in Microsoft Entra ID instantly sets the account state to disabled, which blocks all new authentication requests across the tenant, including password-based, certificate-based, and federated sign-ins. This containment action is comprehensive because it denies sign-in attempts regardless of the source IP, device, or client application. Nonetheless, it does not revoke already-issued session tokens, so combined with session revocation it fully severs both active and future access.

  • ✗

    Reset the user's password.

    Why it's wrong here

    Resetting the user's password invalidates the previous credential so the attacker can no longer use password-based authentication, but it does not invalidate existing access tokens or refresh tokens that were issued before the reset. An attacker holding an active token can continue to access Microsoft Graph, SharePoint, or mail until that token expires, which can be up to 90 minutes for access tokens and longer for refresh tokens. While password reset is a necessary recovery step, it is not the immediate containment action required to stop an active session.

  • ✗

    Block sign-ins from the user's IP address.

    Why it's wrong here

    Blocking sign-ins from the user's IP address only restricts authentication requests originating from that specific IP, while an attacker can easily pivot to a different IP, use a proxy, or leverage a VPN to continue signing in. Furthermore, if the user's legitimate IP is shared or dynamically assigned, this action can inadvertently lock out the user or other users on the same network, causing availability issues without providing comprehensive containment. This approach is too narrow and does not address the underlying account compromise.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.