SC-200 Respond to security incidents Practice Question
Your organization has a hybrid identity environment with Microsoft Entra ID (Azure AD) and on-premises Active Directory. You are using Microsoft Defender for Identity (MDI) integrated with Microsoft Defender XDR. An incident is raised indicating that a user account has been compromised because of an anomaly in Kerberos protocol activity. The incident severity is High. You need to contain the incident immediately by disabling the user account across both on-premises and cloud. However, you also want to preserve the account for forensic analysis. What is the recommended course of action?
⚠ Common exam trap
SC-200 often tests the need to disable accounts in both cloud and on-premises environments while preserving them for forensics, and candidates may choose password reset or deletion instead.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
From Microsoft Defender XDR incident, use the action to disable the user account in Microsoft Entra ID and also disable the on-premises account using a playbook that runs a PowerShell script.
Microsoft Defender XDR provides a built-in action to disable a user account in Microsoft Entra ID directly from the incident. For on-premises AD, a playbook with a PowerShell script can disable the account, preserving it for forensic analysis. This approach contains the incident across both environments without deleting the account.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Delete the user account from Microsoft Entra ID and on-premises AD immediately.
Why it's wrong here
Deleting the account destroys the object and its attributes, defeating the requirement to preserve it for forensic analysis, and deletion does not reliably block on-premises Kerberos authentication. It is tempting because deletion feels like decisive containment, and would be correct when no investigation or evidence retention is needed.
- ✗
Reset the user's password in Microsoft Entra ID and force a password change at next logon on-premises.
Why it's wrong here
A password reset leaves the account enabled, so the attacker retains Kerberos ticket and session access; containment requires disabling the identity. It is tempting because credential rotation is a standard remediation, and would be correct when the goal is evicting a compromised password rather than immediately blocking all authentication.
- ✗
Enable conditional access policy to require MFA for the user and revoke all refresh tokens.
Why it's wrong here
Conditional access governs Microsoft Entra ID token issuance and cannot disable the on-premises Active Directory account, so Kerberos authentication against domain controllers continues. It is tempting because MFA and token revocation are strong cloud controls, and would be correct when containing cloud-only token theft rather than a hybrid Kerberos anomaly.
- ✓
From Microsoft Defender XDR incident, use the action to disable the user account in Microsoft Entra ID and also disable the on-premises account using a playbook that runs a PowerShell script.
Why this is correct
Disabling the account in Microsoft Entra ID blocks cloud sign-in, while a playbook running PowerShell disables the on-premises Active Directory account, containing the Kerberos-based compromise across both environments. Disabling rather than deleting preserves the account for forensic analysis.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.