Question 230 of 1,038
SC-200 Respond to security incidents Practice Question
Your organization uses Microsoft Defender for Cloud Apps. A security investigator discovers that a user's session token was stolen and used to access sensitive data in SharePoint Online from an anomalous IP address. You need to immediately revoke the attacker's access while minimizing impact on the legitimate user. What should you do?
⚠ Common exam trap
Candidates often confuse session-level remediation (requiring re-authentication for a specific session) with account-level remediation (suspending the user or resetting passwords), failing to recognize that the stolen token is independent of the user's credentials and can be invalidated without affecting other sessions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
From Microsoft Defender for Cloud Apps, use the 'Require re-authentication' action on the anomalous session.
The 'Require re-authentication' action in Microsoft Defender for Cloud Apps immediately terminates the attacker's session by invalidating the stolen session token, forcing the attacker to re-authenticate. This action targets only the anomalous session, leaving the legitimate user's other sessions intact and minimizing disruption. It directly addresses the session token theft without affecting the user's account status or requiring password changes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Suspend the user account in Microsoft Entra ID until the investigation is complete.
Why it's wrong here
Suspending blocks all access, affecting the legitimate user.
- ✓
From Microsoft Defender for Cloud Apps, use the 'Require re-authentication' action on the anomalous session.
Why this is correct
This action revokes the compromised session and forces re-auth, minimizing impact.
- ✗
Revoke all refresh tokens for the user in Microsoft Entra ID.
Why it's wrong here
This logs out the user from all sessions, including legitimate ones.
- ✗
Reset the user's password immediately.
Why it's wrong here
Resetting password does not invalidate an already stolen session token.
About these practice questions
Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →
Last reviewed: Jul 4, 2026
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.
Question Discussion
Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.
Sign in to join the discussion.