Courseiva

SC-200 Respond to security incidents Practice Question

Your company uses Microsoft Defender for Cloud Apps. You discover that a user's account is compromised and used to access a sensitive SharePoint site from an unfamiliar IP. You need to immediately revoke the user's session and force them to re-authenticate. Which action should you take?

⚠ Common exam trap

SC-200 often tests the confusion between blocking an indicator (IP) and revoking the compromised credential/session — candidates pick the IP block because it feels like 'stopping the attacker', but the active session token is what actually needs to be killed.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Apply a policy with the 'Revoke session' action.

The 'Revoke session' governance action in Defender for Cloud Apps invalidates the user's active sessions across connected SaaS apps (SharePoint, Exchange, Teams, etc.) and forces re-authentication, which is the correct immediate response to an active session hijack. It is applied via an access or session policy and works with Conditional Access App Control to terminate the session in real time.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Add the IP to the blocked IP addresses list.

    Why it's wrong here

    Blocking the IP address in Defender for Cloud Apps applies to the entire network range for all users and apps, which is problematic because many organizations share a single egress IP or use a cloud provider's common address pool. This coarse-grained action would deny access to many legitimate users whose traffic originates from the same IP, and it may not even stop the compromised session if the attacker is using a different IP or a client that rotates addresses. It also requires the IP to be known and static, making it an unreliable and overly broad response.

  • ✗

    Create a governance action to suspend the user.

    Why it's wrong here

    Suspending the user via a governance action disables the entire account, which interrupts all of the user's activities across every connected app and typically requires manual intervention to restore access. For a single anomalous session, this is disproportionate and may cause business disruption, especially if the user is a service account or has regular work. Moreover, token-based applications may continue honoring existing access tokens for a period after suspension, so this action does not guarantee an immediate kill of the active session.

  • ✗

    Send a notification to the user to change their password.

    Why it's wrong here

    Sending a password-change notification is a preventive measure that relies on the user's manual action and does nothing to terminate the active session that triggered the alert. The attacker can continue using the current session until the password is changed, and if the session token is a refresh token or persistent cookie, it may survive a password change unless it is explicitly revoked. In Defender for Cloud Apps, notifications are best used to inform the user or admin, not as a containment control.

  • ✓

    Apply a policy with the 'Revoke session' action.

    Why this is correct

    The 'Revoke session' action is the correct governance action because it is a targeted, corrective control that specifically terminates the user's active access to the cloud app without disabling the account. Defender for Cloud Apps works with Conditional Access App Control to remove the session cookie and force a fresh authentication with the identity provider. This immediately stops the attacker's access while preserving the user's ability to sign in again after the risk is mitigated.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.