SC-200 Respond to security incidents Practice Question
You receive an alert in Microsoft Sentinel indicating a potential privilege escalation using the 'AzureHound' tool. You need to determine if the alert is a true positive. What is the first step you should take?
⚠ Common exam trap
SC-200 often tests the ordering of incident response steps, so candidates who jump to containment (blocking the account) instead of first validating the alert with identity audit logs pick the wrong answer.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Check the user's recent activity and the targeted resource in Microsoft Entra ID audit logs
To determine whether an AzureHound privilege-escalation alert is a true positive, you must validate the underlying identity activity — specifically what the user did and which resource was targeted — using Microsoft Entra ID audit logs. AzureHound enumerates Microsoft Entra ID/Entra ID objects and permissions, so the audit trail of directory reads, role assignments, or consent grants is the authoritative evidence. This confirms or refutes the alert before taking disruptive action.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Check the user's recent activity and the targeted resource in Microsoft Entra ID audit logs
Why this is correct
Reviewing Microsoft Entra ID audit logs exposes the specific directory operations AzureHound performs, such as role assignments and service principal enumeration, letting you confirm whether the flagged activity is genuine privilege-escalation reconnaissance rather than benign administrative behaviour. This directly satisfies the stem's requirement to validate the alert before escalating.
- ✗
Review the Microsoft Defender for Cloud recommendation for the resource
Why it's wrong here
Defender for Cloud recommendations address configuration posture and hardening, not the identity-based reconnaissance and privilege-escalation behaviour AzureHound generates, so they cannot confirm this alert. It is tempting because recommendations guide remediation, and would be correct when investigating a misconfiguration finding rather than an active identity attack.
- ✗
Block the user account immediately
Why it's wrong here
Blocking the account immediately is a containment action, not an investigation step, and it destroys the session evidence needed to confirm whether AzureHound actually performed privilege escalation. It is tempting during suspected compromise, and would be correct once triage confirms a true positive requiring immediate containment.
- ✗
Run a full antivirus scan on all devices
Why it's wrong here
AzureHound enumerates Microsoft Entra ID objects and relationships through APIs; it writes no files to endpoints, so an antivirus scan yields no evidence about the alert. It is tempting as a familiar malware response, and would be correct had the alert indicated file-based malware on the devices.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.