SC-200 Respond to security incidents Practice Question
Which TWO actions should you take when responding to a confirmed data exfiltration incident involving Microsoft 365? (Choose two.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Revoke user sessions in Microsoft Entra ID
Options B and C are correct. When responding to a confirmed data exfiltration incident involving Microsoft 365, you should contain the threat by revoking user sessions in Microsoft Entra ID (option B) to prevent further unauthorized access, and investigate by reviewing audit logs in the Microsoft Purview compliance portal (option C) to determine the scope and impact of the exfiltration. Option A (resetting passwords for all users) is excessive and disruptive; instead, focus on resetting passwords for compromised accounts only. Option D (disabling all external sharing in SharePoint) is too broad and may disrupt legitimate business operations. Option E (blocking all access to the tenant) is premature and would cause significant operational disruption.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Reset passwords for all users
Why it's wrong here
Resetting every user's password is disproportionate and does not immediately revoke the attacker's already-issued refresh tokens or active sessions. It is tempting as a credential-theft response, but the correct action revokes sessions for the compromised account, which password resets alone may not achieve.
- ✓
Revoke user sessions in Microsoft Entra ID
Why this is correct
Revoking sessions in Microsoft Entra ID invalidates refresh and access tokens immediately, cutting off the compromised account's continued access. This satisfies the stem's requirement to contain a confirmed exfiltration, since password resets alone leave existing tokens valid until expiry.
- ✓
Review audit logs in Microsoft Purview compliance portal
Why this is correct
Audit logs in the Microsoft Purview compliance portal record file access, sharing and download events, letting investigators scope the exfiltration, identify affected users and establish a timeline. This satisfies the stem's requirement for a response action that supports confirmed-incident investigation and evidence collection.
- ✗
Disable all external sharing in SharePoint
Why it's wrong here
Disabling external sharing tenant-wide removes a legitimate collaboration control but does not revoke the exfiltrating account's active sessions or access tokens. It is tempting because sharing enabled the leak, yet the correct response targets the compromised identity and its existing authenticated sessions.
- ✗
Block all access to the tenant
Why it's wrong here
Blocking all tenant access halts legitimate business operations and locks out responders, while exfiltration is contained by revoking the compromised account's sessions and tokens. It is tempting as an emergency stop, but tenant-wide lockout suits a full ransomware or infrastructure compromise, not a scoped data exfiltration.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.