Courseiva

SC-200 Respond to security incidents Practice Question

Your organization uses Microsoft Defender for Cloud Apps. A security investigator discovers that a user's session token was stolen and used to access sensitive data in SharePoint Online from an anomalous IP address. You need to immediately revoke the attacker's access while minimizing impact on the legitimate user. What should you do?

⚠ Common exam trap

Candidates often confuse session-level remediation (requiring re-authentication for a specific session) with account-level remediation (suspending the user or resetting passwords), failing to recognize that the stolen token is independent of the user's credentials and can be invalidated without affecting other sessions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

From Microsoft Defender for Cloud Apps, use the 'Require re-authentication' action on the anomalous session.

The 'Require re-authentication' action in Microsoft Defender for Cloud Apps immediately terminates the attacker's session by invalidating the stolen session token, forcing the attacker to re-authenticate. This action targets only the anomalous session, leaving the legitimate user's other sessions intact and minimizing disruption. It directly addresses the session token theft without affecting the user's account status or requiring password changes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Suspend the user account in Microsoft Entra ID until the investigation is complete.

    Why it's wrong here

    Suspending the user account in Microsoft Entra ID is a tenant-wide, all-or-nothing action that blocks authentication for every session, not just the anomalous one. This forces the legitimate user to lose access to all applications and services, causing unnecessary business disruption and potentially triggering additional security alerts for the user's frustrated re-entry attempts. While it does halt the attacker's continued use of the compromised session, Defender for Cloud Apps offers a more granular, session-specific response that contains the threat without disabling the entire identity.

  • ✓

    From Microsoft Defender for Cloud Apps, use the 'Require re-authentication' action on the anomalous session.

    Why this is correct

    The 'Require re-authentication' action is a session-level conditional access app control in Microsoft Defender for Cloud Apps that terminates only the specific anomalous session, leaving the user's other active sessions unaffected. It forces both the user and the attacker to re-authenticate, effectively invalidating the stolen access token for that session and any associated refresh token for that session context. Because it is applied solely to the identified risky session, it minimizes user productivity loss while successfully revoking the attacker's unauthorized access, making it the most targeted and proportionate response.

  • ✗

    Revoke all refresh tokens for the user in Microsoft Entra ID.

    Why it's wrong here

    Revoking all refresh tokens in Microsoft Entra ID invalidates the user's long-term tokens across every device and application, forcing every session to require a fresh sign-in. This is a broad, tenant-wide revocation that disrupts the legitimate user's sessions on all endpoints, not just the compromised one, and it can be particularly damaging if the user relies on multiple devices. Additionally, it does not immediately invalidate an already-issued access token, which may remain valid until its expiry, leaving a short window for the attacker to continue using the stolen session token.

  • ✗

    Reset the user's password immediately.

    Why it's wrong here

    Resetting the user's password only affects future authentication attempts and does not invalidate the access token or refresh token already issued for the compromised session. An attacker who has stolen a session token can continue to access resources until that token expires, because the resource owner grants access based on the token's validity, not the account password. This action also forces the legitimate user to go through a password change, causing friction, but it fundamentally fails to contain the active session compromise. A session-level re-authentication or token revocation is required to cut off the attacker's current access.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.