Courseiva

SC-200 Respond to security incidents Practice Question

Which TWO actions should you take when responding to a confirmed data exfiltration incident involving Microsoft 365? (Choose two.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Revoke user sessions in Microsoft Entra ID

Options B and C are correct. When responding to a confirmed data exfiltration incident involving Microsoft 365, you should contain the threat by revoking user sessions in Microsoft Entra ID (option B) to prevent further unauthorized access, and investigate by reviewing audit logs in the Microsoft Purview compliance portal (option C) to determine the scope and impact of the exfiltration. Option A (resetting passwords for all users) is excessive and disruptive; instead, focus on resetting passwords for compromised accounts only. Option D (disabling all external sharing in SharePoint) is too broad and may disrupt legitimate business operations. Option E (blocking all access to the tenant) is premature and would cause significant operational disruption.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Reset passwords for all users

    Why it's wrong here

    Resetting every user's password is disproportionate and does not immediately revoke the attacker's already-issued refresh tokens or active sessions. It is tempting as a credential-theft response, but the correct action revokes sessions for the compromised account, which password resets alone may not achieve.

  • ✓

    Revoke user sessions in Microsoft Entra ID

    Why this is correct

    Revoking sessions in Microsoft Entra ID invalidates refresh and access tokens immediately, cutting off the compromised account's continued access. This satisfies the stem's requirement to contain a confirmed exfiltration, since password resets alone leave existing tokens valid until expiry.

  • ✓

    Review audit logs in Microsoft Purview compliance portal

    Why this is correct

    Audit logs in the Microsoft Purview compliance portal record file access, sharing and download events, letting investigators scope the exfiltration, identify affected users and establish a timeline. This satisfies the stem's requirement for a response action that supports confirmed-incident investigation and evidence collection.

  • ✗

    Disable all external sharing in SharePoint

    Why it's wrong here

    Disabling external sharing tenant-wide removes a legitimate collaboration control but does not revoke the exfiltrating account's active sessions or access tokens. It is tempting because sharing enabled the leak, yet the correct response targets the compromised identity and its existing authenticated sessions.

  • ✗

    Block all access to the tenant

    Why it's wrong here

    Blocking all tenant access halts legitimate business operations and locks out responders, while exfiltration is contained by revoking the compromised account's sessions and tokens. It is tempting as an emergency stop, but tenant-wide lockout suits a full ransomware or infrastructure compromise, not a scoped data exfiltration.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.