SC-200 Respond to security incidents Practice Question
You are responding to a phishing incident. The investigation reveals that a user clicked a link in a phishing email and entered credentials on a fake site. You need to contain the incident and prevent further compromise. What should you do first?
⚠ Common exam trap
The trap here is that candidates focus on blocking the phishing URL or deleting the email (technical controls for the attack vector) instead of recognizing that the core containment priority is neutralizing the compromised credentials (the attacker's foothold).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Reset the user's password and revoke sessions.
The immediate priority when credentials have been compromised is to invalidate them, preventing the attacker from using them for further access. Resetting the password and revoking sessions (e.g., via Microsoft Entra ID 'Revoke-AzureADUserAllRefreshToken' or 'Revoke-MgUserSignInSession') ensures the attacker cannot authenticate again, even if they have the password hash or active tokens. This aligns with the NIST SP 800-61 incident response containment phase.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Report the phishing site to Microsoft.
Why it's wrong here
Reporting the phishing URL to Microsoft through the Microsoft Defender portal or the Microsoft Security Intelligence site adds the domain to reputation feeds and can help block it for other tenants, but it does not invalidate the credentials already captured by the attacker. Since the attacker can still authenticate with the stolen password or use an existing session, this action has no immediate containment effect for the compromised account. It is useful follow-up for community protection, but not the correct first step in incident response.
- ✗
Block the phishing URL in Microsoft Defender for Office 365.
Why it's wrong here
Blocking the phishing URL in the Tenant Allow/Block List of Microsoft Defender for Office 365 prevents future email delivery or clicks on that link, but the attacker has already received the user's credentials from the original click. The block does not reset the user's password, does not revoke any refresh or access tokens issued before the block, and does not terminate the attacker's active session. Therefore, it only mitigates future exposure, not the current compromise.
- ✓
Reset the user's password and revoke sessions.
Why this is correct
Resetting the user's password changes the credential so the stolen password is no longer valid for authentication, while revoking sessions through Microsoft Entra ID invalidates any refresh tokens and access tokens the attacker may have obtained. This directly severs the attacker's ability to continue using the compromised account, including mailbox access and other applications. It is the proper immediate containment action for a credential-phishing incident.
- ✗
Delete the phishing email from the user's mailbox.
Why it's wrong here
Deleting the phishing email from the mailbox removes the original lure and reduces the chance of another user clicking the same link, but it has no effect on the credentials that were already phished. The attacker can still authenticate using the stolen password or a session token, and email deletion does not trigger any identity-layer revocation. This action is purely housekeeping and does not address the root cause of the compromise.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.