SC-200 Manage a security operations environment Practice Question
Your organization uses Microsoft Defender for Identity. You receive an alert about a suspicious Kerberos ticket request. What is the most appropriate first step?
⚠ Common exam trap
The trap here is that candidates often jump to immediate remediation actions like disabling accounts or resetting passwords, forgetting that the first step in any incident response process (as per NIST 800-61 and Microsoft's own guidance) is always investigation and triage to confirm the alert and understand the attack context.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Investigate the alert in the Microsoft 365 Defender portal.
The first step when receiving any security alert, including a suspicious Kerberos ticket request from Microsoft Defender for Identity, is to investigate the alert in the Microsoft 365 Defender portal. This portal provides the unified security operations console where you can view the full alert details, related entities, and the MITRE ATT&CK mapping to understand the scope and severity before taking any remediation actions. Prematurely disabling accounts or resetting passwords without investigation can destroy forensic evidence and potentially disrupt legitimate user activity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disable the user account.
Why it's wrong here
Disabling the user account is premature because you have not yet validated whether the alert is a true positive or a false positive. In Microsoft Defender for Identity, alerts can be triggered by unusual but legitimate activity, and disabling the account could disrupt the user's work and any automated services that run under that identity. Additionally, disabling alone does not eliminate malware or other footholds the attacker might have established. Always triage the alert in the Microsoft 365 Defender portal before taking such a disruptive action.
- ✓
Investigate the alert in the Microsoft 365 Defender portal.
Why this is correct
Investigating the alert in the Microsoft 365 Defender portal is the correct first step because it provides the full attack story, including the involved source and target entities, activity timelines, and evidence-based recommendations. The portal correlates signals from Microsoft Defender for Identity with identity and service events, letting you confirm whether the alert is a true positive and determine the scope of compromise. Only after this investigation should you choose a containment or remediation action such as resetting the password or disabling the account.
- ✗
Reset the user's password.
Why it's wrong here
Resetting the user's password is a common containment action, but performing it without prior investigation can mask the alert or miss an active attack path. If the alert is a false positive, the reset is unnecessary and causes user friction; if it is a true positive, the attacker may have already created a secondary credential or scheduled task that a password reset will not remove. Furthermore, resetting a password while account is compromised can tip off the attacker or cause a lockout. You must first investigate in the Microsoft 365 Defender portal to confirm the threat and identify all persistence mechanisms.
- ✗
Reset the krbtgt account password.
Why it's wrong here
Resetting the krbtgt account password is an extreme and highly disruptive operation, as krbtgt is the account used to encrypt and sign all Kerberos ticket-granting tickets (TGTs) in the domain. Doing this invalidates every active TGT, forcing a full re-authentication across the entire environment; it is normally reserved for recovery from a golden ticket attack after careful planning and is never an initial response step. The scenario does not indicate a compromise of the Kerberos infrastructure, so this action would be disproportionate and could cause a domain-wide outage. Investigate first to confirm the identity alert and understand the actual attack pattern.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.