SC-200 Respond to security incidents Practice Question
You are investigating a compromised user account in Microsoft Sentinel. You have identified that the attacker used the account to send phishing emails internally. You need to contain the threat by disabling the account and revoking all active sessions. Which Microsoft Sentinel feature should you use to perform these actions directly from the incident?
⚠ Common exam trap
Candidates often confuse automation rules or playbooks with direct entity actions; automation rules automate responses but do not provide manual containment buttons.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Entity action
Microsoft Sentinel's entity actions allow analysts to take direct containment steps on entities like users, devices, and IP addresses. For a user entity, actions include disabling the account in Microsoft Entra ID and revoking all active sessions. These actions are available from the incident investigation graph or entity pane, enabling rapid response without switching to the Entra portal.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Automation rule
Why it's wrong here
Automation rules are used to trigger playbooks or assign incidents based on conditions, but they do not provide direct interactive actions like disabling an account or revoking sessions. They are for orchestration, not manual containment. While a playbook could perform these actions, the question asks for a feature to do it directly from the incident, which is the entity action.
- ✓
Entity action
Why this is correct
In Microsoft Sentinel, when you select a user entity in an incident, you can perform entity actions such as 'Disable user' and 'Revoke sessions' directly from the investigation graph or entity pane. These actions integrate with Microsoft Entra ID to immediately contain the threat. This is the fastest way to respond without leaving Sentinel.
- ✗
Workbook
Why it's wrong here
Workbooks are used for visualization and reporting in Microsoft Sentinel. They do not provide interactive containment actions like disabling accounts or revoking sessions. While they can display data about the incident, they are not used for response actions. The analyst needs an action-oriented feature, not a reporting tool.
- ✗
Hunting query
Why it's wrong here
Hunting queries are used to proactively search for threats across data sources. They do not perform containment actions. You could write a query to find the user, but you cannot disable the account or revoke sessions from within a hunting query. The question requires a response action, not a search.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.