SC-200 Respond to security incidents Practice Question
You are handling an incident where a user's account was used to access sensitive data from an unusual location. Microsoft Entra ID Identity Protection flagged the sign-in as risky. You need to determine if the account is compromised. Which investigation step should you perform first?
⚠ Common exam trap
The trap is jumping to remediation actions (block, reset password) before completing the investigation; candidates may think immediate action is best, but the question asks for the first step in determining if the account is compromised.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Review the sign-in details and compare with the user's typical behavior
Before taking any remediation action, you should first review the sign-in details and compare them with the user's typical behavior to determine if the account is actually compromised. This investigation step provides context and helps avoid unnecessary disruptions. Only after confirming a compromise should you proceed with actions like blocking or password reset.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Block the user from signing in
Why it's wrong here
Blocking the user from signing in is a containment action that should be applied only after the sign-in has been confirmed as malicious. If the sign-in is actually legitimate—for example, a user on a new device or from a new location—a premature block will cause unnecessary operational disruption and may tip off the user to an ongoing incident investigation. Furthermore, applying an account lock without first reviewing sign-in logs could delete active session evidence or obscure the true root cause, violating the 'identify before contain' principle in incident response.
- ✗
Force a password reset for the user
Why it's wrong here
Forcing a password reset without first confirming the account is genuinely compromised is dangerous because it can alert an active attacker who may still hold session tokens or a persistent backdoor, prompting them to escalate privileges or exfiltrate data quickly. Even if reset is justified, it is not a complete remediation: an attacker with a stolen refresh token may remain authenticated unless sessions and tokens are explicitly revoked. Proper triage requires examining sign-in logs, risk indicators, and authentication factors before taking credential-based remediation steps.
- ✗
Check if the device used is managed by Intune
Why it's wrong here
Checking whether the device is managed by Intune provides only a single contextual attribute and does not confirm or deny account compromise. A device can be Intune-managed and compliant while the sign-in originates from an attacker who has compromised the user's credentials or stolen a session token on that very device; conversely, a user on a personal, non-managed device could trigger a false positive alert. The decisive evidence is whether the sign-in behavioral characteristics—IP geolocation, user agent, time, frequency, and risk score—match the user's established baseline, not merely the device's enrollment status.
- ✓
Review the sign-in details and compare with the user's typical behavior
Why this is correct
Reviewing the sign-in details and comparing them with the user's typical behavior is the correct initial triage action because Entra ID sign-in logs contain rich data—client IP, latitude/longitude, user agent, authentication method, device ID, and risk labels (e.g., impossible travel, unfamiliar sign-in properties, anonymized IP)—that can be correlated against the user's historical baseline. This behavioral analytics approach validates whether the sign-in is truly anomalous before any containment steps are taken, which is consistent with the 'identify-scope-contain' incident response lifecycle. Without this evidence-based review, actions like resetting credentials or blocking the account would be premature and potentially misguided, either disrupting a legitimate sign-in or failing to address a real compromise.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.