SC-200 Remediation Practice Question
You are investigating a security incident involving a compromised user account. The attacker used the account to access sensitive data in SharePoint Online. Which TWO actions should you take to remediate the incident? (Choose two.)
⚠ Common exam trap
Distinguish between investigative actions (reviewing logs) and remediation actions (revoking tokens, disabling account). Immediate remediation stops the breach; investigation follows.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Revoke all refresh tokens for the user.
Option B is correct because revoking all refresh tokens for the compromised user immediately invalidates the OAuth 2.0 refresh tokens that the attacker could use to silently obtain new access tokens for SharePoint Online and other Microsoft 365 resources, cutting off their persistent access. Option C is correct because disabling the user account in Microsoft Entra ID blocks any further authentication attempts with that identity, preventing the attacker from signing in again while the incident is contained. Option A is not the best remediation action here because resetting the password alone does not invalidate existing refresh tokens, so the attacker could retain access until those tokens expire. Option D is a detection/investigation step rather than a remediation action, and Option E is a preventive control that does not immediately stop an active compromise.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Reset the user's password.
Why it's wrong here
Resetting the password alone leaves the attacker's issued refresh tokens valid, so SharePoint access continues until those sessions are revoked. It is tempting because credential reset is a standard containment step, and it would suffice where no persistent tokens or sessions exist.
- ✓
Revoke all refresh tokens for the user.
Why this is correct
Revoking refresh tokens immediately invalidates the attacker's existing sessions, preventing token renewal and further access to SharePoint Online. This satisfies the containment constraint by cutting off persistent access tied to the compromised account, since access tokens alone expire quickly but refresh tokens sustain the intrusion.
- ✓
Disable the user account in Microsoft Entra ID.
Why this is correct
Disabling the account in Microsoft Entra ID immediately blocks all further authentication and token issuance for the compromised identity, halting the attacker's access to SharePoint Online and other resources. This contains the incident at the identity layer before investigating scope and resetting credentials.
- ✗
Review the sign-in logs to determine the extent of the breach.
Why it's wrong here
Reviewing sign-in logs establishes scope and timeline but changes nothing, and remediation requires containment actions such as disabling the account or revoking sessions. It is tempting because log review is the correct first step during the investigation phase, before remediation begins.
- ✗
Create a Conditional Access policy to require MFA for the user.
Why it's wrong here
A Conditional Access MFA policy governs future sign-ins and does not evict the attacker's existing tokens or sessions, leaving SharePoint access intact. It is tempting because MFA blocks credential replay, making it the right control when hardening access preventively rather than responding to an active compromise.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.