SC-200 Respond to security incidents Practice Question
Your organization uses Microsoft Defender for Cloud Apps and Microsoft Sentinel. An alert indicates that an external IP address is downloading large amounts of data from a SharePoint site containing confidential documents. The activity is coming from a valid user account that appears to be compromised. What should you do first to stop the data exfiltration?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Suspend the user account in Microsoft Entra ID
The first priority is to immediately stop the ongoing data exfiltration by suspending the compromised user account in Microsoft Entra ID. This disables the attacker's access via that account, halting the download. Blocking the external IP address (Option C) is less effective because the attacker could switch IPs. Changing SharePoint permissions (Option D) or deleting documents (Option A) would not stop the current download session as quickly as suspending the account.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Delete the confidential documents from SharePoint
Why it's wrong here
Deleting documents destroys the evidence needed for investigation and does not revoke the compromised account's active session, so exfiltration continues via cached tokens. It is tempting as a containment reflex, and would suit permanent data disposal under a retention policy, but not stopping an in-progress breach.
- ✓
Suspend the user account in Microsoft Entra ID
Why this is correct
Suspending the account in Microsoft Entra ID immediately blocks the compromised identity's authentication, halting the ongoing SharePoint download before further data leaves. Containment precedes investigation, so revoking the valid credentials stops exfiltration at its source rather than merely alerting on it.
- ✗
Block the external IP address in Microsoft Defender for Cloud Apps
Why it's wrong here
Blocking the IP in Defender for Cloud Apps stops that address only; the attacker can rotate IPs, and the compromised valid account retains access. Disabling or revoking the user's sessions and credentials addresses the compromised identity itself. IP blocking suits known malicious infrastructure, not account compromise.
- ✗
Change the SharePoint site permissions to deny access
Why it's wrong here
Altering site permissions does not terminate the compromised user's existing authenticated session or revoke its tokens, so downloads continue. It is tempting because permission changes harden access long-term, and would be right for removing a departed contractor's standing access, not halting live exfiltration.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on SC-200
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Your organization uses Microsoft Defender for Cloud Apps. You discover that a user has been accessing sensitive data from an anonymous IP address. The user's account appears to be compromised. You need to prevent further data exfiltration. What should you do?
medium- A.Disable the user account in Microsoft Entra ID.
- B.Create an IP range policy in Defender for Cloud Apps to block the anonymous IP.
- C.Change the user's password and revoke sessions.
- ✓ D.Suspend the user in Microsoft Defender for Cloud Apps.
Why D: Suspending the user in Microsoft Defender for Cloud Apps is the correct immediate action because it temporarily blocks the user from accessing cloud apps and resources without deleting or disabling the account, preserving forensic evidence while stopping exfiltration. This is a built-in remediation action in Defender for Cloud Apps designed for compromised accounts. It is faster and more targeted than disabling the account in Entra ID, which would also block legitimate access and may not be reversible as cleanly.
Variation 2. You are investigating a suspicious sign-in reported in Microsoft Defender for Cloud Apps. The activity shows that a user accessed a sensitive SharePoint site from an anonymous IP address. What is the most effective immediate response to prevent further access?
medium- ✓ A.Suspend the user account in Microsoft 365 Defender.
- B.Change the SharePoint site permissions to remove the user's access.
- C.Disable the user's device in Microsoft Intune.
- D.Add the anonymous IP address to the blocked IP address list in Conditional Access.
Why A: Suspending the user account in Microsoft 365 Defender is the most effective immediate response to prevent further access when a suspicious sign-in from an anonymous IP is detected. Suspending the account immediately blocks all sign-ins and access to Microsoft 365 services, including SharePoint, stopping any ongoing malicious activity. This is a containment action that takes effect quickly across all services.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.