Courseiva

SC-200 Respond to security incidents Practice Question

You are investigating an incident in Microsoft Sentinel where a user account was used to sign in from an unfamiliar location and then accessed multiple sensitive files. Which step is most important to perform first?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Disable the user account and reset the password.

Confirming account compromise and immediately disabling the user account is the highest priority to stop further malicious activity. Resetting the password prevents the attacker from using the compromised credentials. Option A is incorrect because blocking the IP address alone may be ineffective if the attacker uses proxies, and it does not secure the account. Option B is incorrect because checking firewall logs is a secondary forensic step that does not address the immediate threat. Option C is incorrect because reviewing file permissions should be done after securing the account.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Block the IP address of the unfamiliar location.

    Why it's wrong here

    Blocking the source IP presumes the sign-in was malicious and ignores that the account itself may be compromised; the immediate priority is confirming whether the sign-in and file access were legitimate. IP blocking fits confirmed malicious infrastructure, not an unverified unfamiliar-location alert.

  • ✗

    Check firewall logs for related network traffic.

    Why it's wrong here

    Firewall logs record network-layer connections, not the identity-based sign-in and file-access events already surfaced in Sentinel; the unfamiliar-location sign-in and subsequent file reads are Entra ID and SharePoint/OneDrive audit records. Firewall logs suit tracing command-and-control or lateral movement traffic once an identity compromise has been confirmed.

  • ✗

    Review file permissions on the accessed files.

    Why it's wrong here

    File permissions describe the access control configuration, not whether this account's access was authorised; permissions review cannot establish whether the sign-in was legitimate. It suits auditing excessive or misconfigured access rights after the incident's scope is known.

  • ✓

    Disable the user account and reset the password.

    Why this is correct

    Disabling the account and resetting the password immediately contains the active compromise, satisfying the stem's priority of stopping ongoing malicious access before deeper forensic scoping. This neutralises the attacker's session and credentials, preventing further sensitive file exfiltration while investigation continues in Microsoft Sentinel.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.