SC-200 Respond to security incidents Practice Question
Your organization uses Microsoft Defender for Identity and Microsoft Defender XDR. You receive an alert about a suspicious LDAP query originating from a domain controller. The alert indicates potential use of the DCSync attack technique. What is the most effective immediate action to contain the attack?
⚠ Common exam trap
A common mix-up: candidates confuse DCSync with a standard LDAP query and choose to block LDAP traffic, not realizing DCSync uses the DRSR protocol over RPC, and that disabling the offending account is the precise immediate containment step.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Disable the account that initiated the suspicious replication request.
The DCSync attack abuses the Directory Replication Service Remote Protocol (MS-DRSR) to impersonate a domain controller and request replication of credentials. Disabling the compromised account that initiated the suspicious LDAP replication request immediately stops the attacker's ability to request further replication, effectively containing the attack at the source without disrupting the entire domain.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Block all LDAP traffic at the firewall.
Why it's wrong here
Blocking all LDAP traffic at the firewall is ineffective and damaging because Directory Replication Service (DRS/RPC) traffic — the protocol used for DCsync-style replication — does not rely on LDAP ports (389/636). It would also interrupt legitimate authentication, lookups, and group policy processing across the domain, causing an availability incident. The attack is already using the compromised account's replication rights, so LDAC filtering does not address the root cause or stop the ongoing exfiltration.
- ✗
Restart the domain controller to clear any malicious processes.
Why it's wrong here
Restarting the domain controller removes only transient processes, but the malicious replication is performed through legitimate Windows APIs and directory replication primitives invoked by the compromised account — these are not artifacts that a reboot will eliminate. The account remains enabled with its replication permissions (Replicating Directory Changes/Directory Changes All), so the attacker can simply rerun the DCSync operation after the DC comes back online. Additionally, an unplanned DC restart risks database integrity issues and does nothing to revoke the identity that is the actual attack vehicle.
- ✓
Disable the account that initiated the suspicious replication request.
Why this is correct
Disabling the account is the correct immediate containment action because DCSync attacks (like Golden Ticket or DCshadow pre-staging) rely on the compromised identity having directory replication permissions, and disabling it blocks that account from authenticating or invoking DRS replication any further. This directly severs the attacker's current access path and halts the unauthorized replication request without requiring a full DC restart or broad network disruption. After disabling, the SID of the account can be added to a honeytoken or monitored for any further attempts during incident response. It is the fastest, least-destructive way to stop the bleeding.
- ✗
Reset the krbtgt account password twice.
Why it's wrong here
Resetting the krbtgt account password twice is a recovery procedure specifically designed to invalidate forged Kerberos tickets after a Golden Ticket attack, not to stop an active DCSync replication incident. It does not affect the compromised account's permissions or its ability to perform replication again. Moreover, a double reset is a delicate, staged process that must be coordinated with replication latency and trust relationships; doing it prematurely during containment can cause authentication outages across the domain. This action is appropriate later in the remediation phase, but it is not an immediate containment step.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.