Courseiva

SC-200 Respond to security incidents Practice Question

You receive an alert in Microsoft Sentinel indicating a potential privilege escalation using the 'AzureHound' tool. You need to determine if the alert is a true positive. What is the first step you should take?

⚠ Common exam trap

SC-200 often tests the ordering of incident response steps, so candidates who jump to containment (blocking the account) instead of first validating the alert with identity audit logs pick the wrong answer.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Check the user's recent activity and the targeted resource in Microsoft Entra ID audit logs

To determine whether an AzureHound privilege-escalation alert is a true positive, you must validate the underlying identity activity — specifically what the user did and which resource was targeted — using Microsoft Entra ID audit logs. AzureHound enumerates Microsoft Entra ID/Entra ID objects and permissions, so the audit trail of directory reads, role assignments, or consent grants is the authoritative evidence. This confirms or refutes the alert before taking disruptive action.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Check the user's recent activity and the targeted resource in Microsoft Entra ID audit logs

    Why this is correct

    Reviewing Microsoft Entra ID audit logs exposes the specific directory operations AzureHound performs, such as role assignments and service principal enumeration, letting you confirm whether the flagged activity is genuine privilege-escalation reconnaissance rather than benign administrative behaviour. This directly satisfies the stem's requirement to validate the alert before escalating.

  • ✗

    Review the Microsoft Defender for Cloud recommendation for the resource

    Why it's wrong here

    Defender for Cloud recommendations address configuration posture and hardening, not the identity-based reconnaissance and privilege-escalation behaviour AzureHound generates, so they cannot confirm this alert. It is tempting because recommendations guide remediation, and would be correct when investigating a misconfiguration finding rather than an active identity attack.

  • ✗

    Block the user account immediately

    Why it's wrong here

    Blocking the account immediately is a containment action, not an investigation step, and it destroys the session evidence needed to confirm whether AzureHound actually performed privilege escalation. It is tempting during suspected compromise, and would be correct once triage confirms a true positive requiring immediate containment.

  • ✗

    Run a full antivirus scan on all devices

    Why it's wrong here

    AzureHound enumerates Microsoft Entra ID objects and relationships through APIs; it writes no files to endpoints, so an antivirus scan yields no evidence about the alert. It is tempting as a familiar malware response, and would be correct had the alert indicated file-based malware on the devices.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.