SC-200 Respond to security incidents Practice Question
Your organization has Microsoft Defender XDR enabled. An incident is generated for a user who clicked a phishing link in an email. The analyst needs to automatically disable the user's mailbox for suspicious activity. Which automated action should the analyst configure in a Microsoft Sentinel automation rule?
⚠ Common exam trap
A common mix-up: candidates confuse 'disabling the mailbox' with other remediation actions like password reset or email deletion, failing to recognize that only a playbook with the Microsoft 365 Defender connector can directly execute the mailbox disablement action in Exchange Online.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Run a playbook that uses the Microsoft 365 Defender connector to disable the mailbox.
The goal is to disable the user's mailbox, which is a Microsoft 365 Exchange Online action. A Microsoft Sentinel automation rule can trigger a playbook that uses the Microsoft 365 Defender connector to execute the 'Disable mailbox' action directly against Exchange Online, effectively suspending the user's ability to send or receive email. This aligns with the requirement to automatically respond to a phishing incident by disabling the compromised mailbox.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Run a playbook that deletes the phishing email from the user's inbox.
Why it's wrong here
Deleting the phishing email from the user's inbox removes only the visible malicious message, but it does not disable the compromised mailbox or revoke access for an attacker who may already possess session tokens or have created inbox rules. The user account remains active, and the attacker can continue to send, receive, or exfiltrate email. This is a remediation action, not a containment action, so it fails to disable the mailbox as required.
- ✗
Configure an automation rule to block the sender IP address in Defender for Cloud Apps.
Why it's wrong here
Blocking the sender's IP address in Defender for Cloud Apps is not the correct remediation because this feature governs access to cloud apps and generates alerts, but it does not control Exchange Online mail flow. Even if the IP is blocked at the network layer, an authenticated attacker using valid credentials would be unaffected, and the action would do nothing to disable the user's mailbox. The Microsoft 365 Defender connector, not the Cloud Apps integration, provides the mailbox-disable action needed here.
- ✗
Run a playbook that resets the user's password.
Why it's wrong here
Resetting the user's password invalidates the known credential, but it does not immediately disable the mailbox, and the attacker may still leverage existing OAuth access tokens, cached credentials, or other session artifacts to continue accessing email. While a password reset is a useful step to discourage further sign-ins, the explicit requirement is to block all mailbox access immediately, which is only achieved by disabling the mailbox itself. This option does not perform the required mailbox-disable action.
- ✓
Run a playbook that uses the Microsoft 365 Defender connector to disable the mailbox.
Why this is correct
Running a playbook that uses the Microsoft 365 Defender connector is the correct approach because this connector exposes a 'Disable mailbox' remediation action designed for incident response scenarios. When triggered from a Microsoft Defender XDR incident, the playbook can execute this action directly against the affected user's mailbox in Exchange Online, immediately preventing further access and exfiltration. This precisely satisfies the requirement to disable the mailbox as a containment step.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.