Courseiva

SC-200 Respond to security incidents Practice Question

You are investigating a compromised user account in Microsoft Sentinel. You have identified that the attacker used the account to send phishing emails internally. You need to contain the threat by disabling the account and revoking all active sessions. Which Microsoft Sentinel feature should you use to perform these actions directly from the incident?

⚠ Common exam trap

Candidates often confuse automation rules or playbooks with direct entity actions; automation rules automate responses but do not provide manual containment buttons.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Entity action

Microsoft Sentinel's entity actions allow analysts to take direct containment steps on entities like users, devices, and IP addresses. For a user entity, actions include disabling the account in Microsoft Entra ID and revoking all active sessions. These actions are available from the incident investigation graph or entity pane, enabling rapid response without switching to the Entra portal.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Automation rule

    Why it's wrong here

    Automation rules are used to trigger playbooks or assign incidents based on conditions, but they do not provide direct interactive actions like disabling an account or revoking sessions. They are for orchestration, not manual containment. While a playbook could perform these actions, the question asks for a feature to do it directly from the incident, which is the entity action.

  • ✓

    Entity action

    Why this is correct

    In Microsoft Sentinel, when you select a user entity in an incident, you can perform entity actions such as 'Disable user' and 'Revoke sessions' directly from the investigation graph or entity pane. These actions integrate with Microsoft Entra ID to immediately contain the threat. This is the fastest way to respond without leaving Sentinel.

  • ✗

    Workbook

    Why it's wrong here

    Workbooks are used for visualization and reporting in Microsoft Sentinel. They do not provide interactive containment actions like disabling accounts or revoking sessions. While they can display data about the incident, they are not used for response actions. The analyst needs an action-oriented feature, not a reporting tool.

  • ✗

    Hunting query

    Why it's wrong here

    Hunting queries are used to proactively search for threats across data sources. They do not perform containment actions. You could write a query to find the user, but you cannot disable the account or revoke sessions from within a hunting query. The question requires a response action, not a search.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.