SC-200 Respond to security incidents Practice Question
You are a SOC analyst at Contoso Ltd. The company uses Microsoft Sentinel and Microsoft Defender XDR. A high-severity incident is generated from a Sentinel analytics rule that detects multiple failed logins followed by a successful login from a geographically unusual location for a user. The incident includes an alert from Microsoft Defender for Identity indicating a possible brute-force attack. The user's account is a privileged administrator. Your organization has strict compliance requirements: any privileged account compromise must be contained within 15 minutes of detection. You have the following tools available: Microsoft Entra ID with Privileged Identity Management (PIM), Microsoft Defender for Cloud Apps, and Microsoft 365 Defender automation rules. The incident is now 5 minutes old. What should you do to meet the compliance requirement?
⚠ Common exam trap
SC-200 often tests the difference between detective controls (alerts, automation rules) and true containment actions (disable account, revoke sessions), tricking candidates into choosing policy-based or notification-based options that do not meet a strict time-bound SLA.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Disable the user account in Microsoft Entra ID immediately.
Disabling the account in Microsoft Entra ID immediately is the fastest, most direct containment action for a confirmed privileged-account compromise. It revokes the account's ability to authenticate and blocks all new sign-ins and token issuance at the identity provider level, satisfying the 15-minute containment SLA. Since the incident is only 5 minutes old and involves a privileged admin, immediate account disablement is the correct incident-response action rather than a detective or policy-based control.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create an automation rule in Microsoft 365 Defender to alert the security team.
Why it's wrong here
Creating an automation rule in Microsoft 365 Defender cannot actually contain the compromised identity. Automation rules act on incidents and alerts—they can send email notifications, assign ownership, or change severity—but they do not have a native action to disable an Entra ID user account or terminate sign-in sessions. Alerting the security team raises awareness but leaves the attacker's access intact, so it fails the core containment objective.
- ✓
Disable the user account in Microsoft Entra ID immediately.
Why this is correct
Disabling the user account in Microsoft Entra ID is the fastest and most direct containment action. Setting the account's AccountEnabled property to false immediately prevents new token issuance and triggers revocation of the user's existing refresh tokens, effectively cutting off access within seconds. This can be done in the Entra admin center or via Microsoft Graph, and it is the recommended first step for a confirmed account compromise because it stops the attacker regardless of which app or resource they are targeting.
- ✗
Create a conditional access policy to block the user's sign-ins.
Why it's wrong here
A Conditional Access policy that blocks the user's sign-ins can eventually prevent authentication, but it is not immediate. Conditional Access policy changes must propagate across Microsoft's infrastructure and can take up to 30 minutes or more to fully take effect, and policies are evaluated only at sign-in time—they do not revoke already-issued access or refresh tokens. Therefore, relying on a Conditional Access block would leave the attacker active during the propagation window and is too slow for emergency containment.
- ✗
Activate PIM and remove the user's role assignments.
Why it's wrong here
Activating Privileged Identity Management (PIM) and removing the user's role assignments requires elevation, justification, and multiple steps, making it significantly slower than directly disabling the account. More critically, PIM only governs privileged roles—removing those assignments would not block the user's normal unprivileged account, so the attacker could still access email, files, or other applications with regular user rights. This action also assumes the user is actually a privileged role member and does not address non-privileged access, making it an incomplete and inefficient containment measure.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.