Courseiva

SC-200 Respond to security incidents Practice Question

Your company uses Microsoft Sentinel with the Microsoft Defender for Cloud Apps connector. An incident is created when a user performs an unusual mass download from SharePoint Online. The playbook assigned to the incident automatically suspends the user account in Microsoft Entra ID. However, after investigation, the user's activity is determined to be legitimate (they were backing up data for a migration). You need to restore the user's account and ensure that the user can access all resources immediately. You also need to update the incident to reflect the findings. What should you do?

⚠ Common exam trap

Many exam-takers think re-running the playbook (Option C) will undo the suspension, but playbooks are not idempotent for reversing actions; they only execute the defined steps at trigger time and cannot retroactively modify past state.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Re-enable the user account in Microsoft Entra ID and set the incident status to Closed with classification 'False positive'.

The user account was suspended by the playbook, so you must manually re-enable it in Microsoft Entra ID to restore access immediately. Setting the incident status to 'Closed' with classification 'False positive' accurately reflects that the alert was triggered by legitimate activity, which is the proper way to close a false positive in Microsoft Sentinel.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Send a new invitation to the user via Microsoft Entra ID and close the incident as resolved.

    Why it's wrong here

    Sending a new B2B collaboration invitation creates a separate guest user object in Microsoft Entra ID rather than re-enabling the existing internal account that the playbook suspended. This leaves the original user account disabled, so the incident's actual entity is never remediated and access to resources that rely on the original user principal name (UPN) is not restored. Closing the incident as resolved afterward is therefore misleading, because no action was taken to address the specific account state that triggered the alert.

  • ✗

    Reset the user's password in Microsoft Entra ID and force a password change at next sign-in.

    Why it's wrong here

    Because the playbook's suspend action sets the account's accountEnabled attribute to false, the login failure is caused by the disabled status, not a forgotten or compromised password. A password reset with a forced change at next sign-in would be ineffective while the account remains disabled, and the user still could not authenticate. Forcing an unnecessary password change also disrupts the user and could trigger conditional access or self-service password reset policies that are irrelevant to the actual false positive.

  • ✗

    Edit the playbook to remove the suspend action and re-run it for the incident.

    Why it's wrong here

    Rewriting the playbook to delete the suspend action and re-running it for the same incident would not undo the previously executed disable step; incident instances do not replay older actions retroactively. Re-running the playbook might only affect subsequent automation runs or future incidents, leaving the account disabled in production. Additionally, modifying a security automation based on a single false positive is an operational overcorrection that weakens the original prevention intent without resolving the current access issue.

  • ✓

    Re-enable the user account in Microsoft Entra ID and set the incident status to Closed with classification 'False positive'.

    Why this is correct

    Once the analyst determines the alert is a false positive, the correct remediation is to re-enable the user account by setting accountEnabled back to true in Microsoft Entra ID, restoring the user's access to Entra ID-protected resources. After making that change, the incident should be closed with classification 'False positive' and a comment documenting that the suspension was erroneous. These two steps together restore service and provide accurate reporting for tuning the analytics rule that caused the false trigger.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.