Courseiva
Question 230 of 1,038
Respond to security incidentshardMultiple ChoiceObjective-mapped

SC-200 Respond to security incidents Practice Question

Your organization uses Microsoft Defender for Cloud Apps. A security investigator discovers that a user's session token was stolen and used to access sensitive data in SharePoint Online from an anomalous IP address. You need to immediately revoke the attacker's access while minimizing impact on the legitimate user. What should you do?

⚠ Common exam trap

Candidates often confuse session-level remediation (requiring re-authentication for a specific session) with account-level remediation (suspending the user or resetting passwords), failing to recognize that the stolen token is independent of the user's credentials and can be invalidated without affecting other sessions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

From Microsoft Defender for Cloud Apps, use the 'Require re-authentication' action on the anomalous session.

The 'Require re-authentication' action in Microsoft Defender for Cloud Apps immediately terminates the attacker's session by invalidating the stolen session token, forcing the attacker to re-authenticate. This action targets only the anomalous session, leaving the legitimate user's other sessions intact and minimizing disruption. It directly addresses the session token theft without affecting the user's account status or requiring password changes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Suspend the user account in Microsoft Entra ID until the investigation is complete.

    Why it's wrong here

    Suspending blocks all access, affecting the legitimate user.

  • From Microsoft Defender for Cloud Apps, use the 'Require re-authentication' action on the anomalous session.

    Why this is correct

    This action revokes the compromised session and forces re-auth, minimizing impact.

  • Revoke all refresh tokens for the user in Microsoft Entra ID.

    Why it's wrong here

    This logs out the user from all sessions, including legitimate ones.

  • Reset the user's password immediately.

    Why it's wrong here

    Resetting password does not invalidate an already stolen session token.

About these practice questions

Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Last reviewed: Jul 4, 2026

Question Discussion

Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.

Loading comments…

Sign in to join the discussion.

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.