SC-200 Respond to security incidents Practice Question
You are investigating a lateral movement incident in Microsoft Defender for Endpoint. The timeline shows that a user's credentials were used from a compromised workstation to access a sensitive server. Which action should you take to contain the incident?
⚠ Common exam trap
The trap here is that candidates focus on the network path (blocking traffic or isolating the workstation) instead of recognizing that credential theft is the core issue, and only resetting the password and revoking sessions stops the lateral movement at its source.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Reset the compromised user's password and revoke all active sessions.
The incident involves lateral movement using stolen credentials. Resetting the compromised user's password and revoking all active sessions immediately invalidates the credentials the attacker used, preventing further unauthorized access to any resource, including the sensitive server. This directly addresses the root cause (credential theft) rather than just blocking network paths or isolating a single device.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disable the sensitive server's network account.
Why it's wrong here
Disabling the sensitive server's network account (its Active Directory computer account) invalidates the server's own domain identity, causing Kerberos authentication failures and breaking file shares, scheduled tasks, or managed services on that host. However, the attacker is not relying on that computer account—they are using a compromised user's credentials—so this action does nothing to invalidate the stolen tokens or prevent authentication from any other machine. It is a disruptive, broad action that fails to address the root cause and may inadvertently trigger availability incidents.
- ✗
Isolate the compromised workstation only.
Why it's wrong here
Isolating only the compromised workstation (e.g., disabling its virtual switch or network adapter) stops traffic originating from that single endpoint, but the attacker has already harvested valid credentials and can pivot from any other domain-joined device using the same stolen tokens. This containment step also leaves the attacker's persistence mechanisms on the network intact and does not revoke any Kerberos tickets or NTLM hashes that were already issued. Without invalidating the compromised identity, the attacker simply uses a different source system for the lateral movement.
- ✗
Block all network traffic from the compromised workstation to the server.
Why it's wrong here
Blocking network traffic from the compromised workstation to the sensitive server only disrupts one specific route (e.g., SMB on port 445) from one source IP, while the attacker can replay the stolen credentials via WinRM, RDP, or SMB from any other compromised machine on the network. This rule is too narrow because the attacker's credentials are not IP-bound; they can authenticate directly to the server from a different workstation or even from a different subnet, making the block easily bypassed. It is a point-in-time containment action that fails to address the underlying credential theft.
- ✓
Reset the compromised user's password and revoke all active sessions.
Why this is correct
Resetting the compromised user's password and revoking all active sessions directly invalidates the stolen credentials—making any cached NTLM hashes, Kerberos TGTs, or delegating artifacts unusable for further authentication. Revoking active sessions (e.g., forcing sign-out or invalidating refresh tokens) ensures that any already-established remote sessions are terminated immediately, rather than waiting for ticket expiry. This stops lateral movement regardless of which workstation the attacker is using or which network path they choose, because the root cause—compromised identity—has been remediated.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SC-200
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Your Microsoft Defender XDR environment generates an incident indicating that a user's account was used to sign in from an anonymous IP address and then accessed sensitive data in SharePoint Online. After confirming the account is compromised, what should be your first containment step?
medium- A.Disable the user account in Microsoft Entra ID
- B.Block the anonymous IP address in the firewall
- C.Review audit logs to determine the extent of data access
- ✓ D.Revoke the user's session and require reauthentication using Microsoft Entra ID Protection
Why D: The correct first containment step is to revoke the user's session and require reauthentication using Microsoft Entra ID Protection. This immediately invalidates all active refresh tokens and access tokens, forcing the attacker out of any ongoing sessions across Microsoft 365 services like SharePoint Online. Disabling the account is a valid containment action, but it does not instantly terminate existing authenticated sessions, leaving a window for the attacker to continue accessing data. Revoking sessions is the fastest way to cut off active access while preserving the account for investigation and remediation.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.