Courseiva

SC-200 Respond to security incidents Practice Question

You are investigating a security incident in Microsoft Sentinel where a user received a phishing email containing a link to a malicious domain. The link was clicked, but no further actions were observed. Which playbook action should you take immediately to prevent potential lateral movement?

⚠ Common exam trap

Many exam-takers confuse a click-only incident with a credential compromise, leading them to choose password reset or session revocation, but the correct first step is to block the malicious domain to contain the network-based threat.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Block the malicious domain on the firewall

The user only clicked the link without performing any further actions (e.g., no credential entry or file download). Blocking the malicious domain on the firewall immediately prevents the user or any other host from reaching the domain, stopping potential lateral movement via subsequent connections. This aligns with the principle of containing the threat at the network layer before it can spread.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Disable the user's account

    Why it's wrong here

    Disabling the user's account is a containment action reserved for confirmed credential compromise or malicious insider activity. In this case, the only evidence is a link click, with no proof of malware execution, credential theft, or unauthorized access, so disabling the account would cause business disruption and potentially alert the adversary while doing nothing to contain the malicious domain itself.

  • ✗

    Revoke the user's active sessions

    Why it's wrong here

    Revoking the user's active sessions is intended for scenarios where authentication tokens or session cookies have been stolen, such as in a token theft or account takeover. Clicking a link does not compromise the user's existing session token; the malicious site could attempt a browser exploit, but that would not invalidate the authenticated session, and this action would still leave the malicious domain reachable by other users.

  • ✗

    Reset the user's password

    Why it's wrong here

    A password reset is warranted only when there is concrete evidence that the user's credentials were phished or otherwise stolen and used by an unauthorized party. Here, no credential submission, authentication anomaly, or suspicious account activity has been observed, so resetting the password would lock the user out without eliminating the threat posed by the malicious domain, which remains accessible to the entire environment.

  • ✓

    Block the malicious domain on the firewall

    Why this is correct

    Blocking the malicious domain at the firewall is a network-based containment action that stops all clients from resolving or connecting to the malicious site, effectively breaking the delivery chain for phishing or malware. It is a reversible, low-impact measure that addresses the root cause regardless of which user or device attempts access, and it aligns with security operations best practice to contain the threat at the earliest opportunity.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.