SC-200 Respond to security incidents Practice Question
Your organization uses Microsoft Defender for Identity. You receive an alert about a suspicious Kerberos activity that may indicate a golden ticket attack. Which of the following actions should you take to investigate this alert?
⚠ Common exam trap
The trap here is that candidates often jump to remediation actions like resetting the krbtgt password or disabling accounts without first investigating the alert details, which can lead to unnecessary disruption or missed context about the attack's scope.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Review the alert details in the Microsoft Defender for Identity portal and analyze related events
The first step in investigating a golden ticket attack alert from Microsoft Defender for Identity is to review the alert details and analyze the related events within the Defender for Identity portal. This allows you to understand the scope of the suspicious Kerberos activity, identify the affected accounts, and correlate the alert with other security signals before taking any remediation actions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Immediately reset the krbtgt account password twice
Why it's wrong here
Immediately resetting the krbtgt account password twice is a domain recovery procedure intended to invalidate any forged Kerberos tickets, but it is a remediation action, not an investigation step. Performing it before you confirm the compromise and identify the attack scope can cause Kerberos authentication failures across the domain and is unnecessary if the alert is a false positive. The investigation should come first; only after confirming a Golden Ticket attack should you execute the reset as part of a structured recovery process.
- ✗
Export the Active Directory event logs to Microsoft Sentinel for analysis
Why it's wrong here
Exporting Active Directory event logs to Microsoft Sentinel is a preparatory step for extended hunting, but it is not the immediate action when an alert fires. Defender for Identity has already ingested and correlated those events into the alert, so the cloud portal presents the needed timeline, entities, and evidence without additional export. Taking time to export raw logs first would delay the investigation and bypass the built-in correlation that makes alerts meaningful.
- ✓
Review the alert details in the Microsoft Defender for Identity portal and analyze related events
Why this is correct
Reviewing the alert details in the Microsoft Defender for Identity portal is the correct first step because the portal aggregates the pertinent events, users, devices, and related alerts into an investigation experience. From the alert page, you can access the full timeline, examine the underlying activities, and pivot to entity profiles, which lets you validate whether the alert is a true positive and understand the attack chain. This analysis provides the context needed to decide on any subsequent containment or remediation.
- ✗
Disable the user account that triggered the alert
Why it's wrong here
Disabling the user account that triggered the alert is a containment action, not an investigation action, and doing it immediately is premature. If the account is actually compromised, disabling it will halt the attacker's visible activity, which could blind you to the full scope of the attack and prevent you from identifying other affected accounts. You should first analyze the alert to confirm the incident; if verified, then apply containment with an understanding of the user's role and access.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.