SC-200 Respond to security incidents Practice Question
Your organization uses Microsoft Defender XDR. A security incident involving a compromised user account has been identified. Which THREE actions should you take to contain and remediate the incident?
⚠ Common exam trap
Many exam-takers think blocking IP addresses (Option C) is a valid containment action, but in Microsoft Defender XDR incidents, IP-based blocking is unreliable due to dynamic IPs and attacker evasion techniques, and the focus should be on identity-level controls like disabling the account and revoking tokens.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Disable the user account in Microsoft Entra ID.
Disabling the user account in Microsoft Entra ID is a critical containment step because it immediately prevents the compromised account from authenticating to any Microsoft cloud services, including Exchange Online, SharePoint, and Teams. This action blocks further unauthorized access at the identity level, which is the foundation of the attack vector in a user account compromise. It is a direct and effective way to stop the attacker from using the account for lateral movement or data exfiltration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Disable the user account in Microsoft Entra ID.
Why this is correct
Disabling the user account in Microsoft Entra ID is the most effective first containment step because it immediately blocks all authentication attempts, including the attacker's stolen credentials, and prevents access to all Microsoft 365 and cloud resources that depend on Entra ID. Even if the attacker holds a valid session token, disabling the account stops new sign-ins and is a strong, reversible measure that preserves the user profile and forensic data for investigation. In Microsoft Defender XDR incident response, this is the recommended manual action to halt attacker activity without deleting any evidence.
- ✓
Reset the user's password.
Why this is correct
Resetting the user's password in Microsoft Entra ID invalidates the attacker's knowledge of the compromised credential, ensuring they cannot authenticate again with the password. However, this action alone does not terminate already-issued access or refresh tokens, so an attacker with an active session can continue accessing resources until those tokens expire or are explicitly revoked. Therefore, password reset is a critical remediation action but must be combined with revoking sessions and tokens to achieve full containment of a compromised account in Defender XDR.
- ✗
Block all IP addresses that the user has connected from.
Why it's wrong here
Blocking all IP addresses that the user has connected from is an imprecise and potentially harmful containment action because the attacker may be operating from a different source IP, and the user's legitimate IP ranges—especially in mobile or remote workforces—are often dynamic or shared via NAT, meaning this can block other users' legitimate traffic. This measure also does not invalidate the attacker's existing session or credentials, so it fails to stop ongoing access. A more targeted approach would use Conditional Access policies to block specific suspicious IPs, but this is not a primary containment step for a compromised user.
- ✓
Revoke all active sessions and tokens for the user.
Why this is correct
Revoking all active sessions and tokens for the user in Microsoft Entra ID terminates the attacker's existing access by invalidating refresh tokens and requiring all clients to re-authenticate, cutting off current sessions across Microsoft Graph, Outlook, SharePoint, and other connected apps. This is a precise and immediate containment action that does not delete the user or their data, making it a necessary follow-up to account disablement and password reset. In Defender XDR, this action is executed from the Entra admin center and directly addresses the 'existing session' attack vector that password reset alone cannot close.
- ✗
Restore the user's mailbox from a backup.
Why it's wrong here
Restoring the user's mailbox from a backup is not a containment action because it does nothing to stop an attacker who still has active credentials or valid tokens, and it may actually overwrite critical forensic evidence if the backup predates or includes attacker modifications. In incident response, restoration is only appropriate after the threat is fully eradicated and the account is secured, and it should be performed using Exchange Online eDiscovery or Litigation Hold to preserve data, not as an immediate response. This action is therefore not a valid step in the Defender XDR containment phase for a compromised user.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on SC-200
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Your organization uses Microsoft Sentinel and Microsoft Defender for Identity. An incident is created for a user whose credentials were used from an unusual location to access sensitive HR data. The user's account is a domain admin. The security team needs to ensure the attacker cannot use the account again. What should you do first?
hard- A.Remove the user from the Domain Admins group
- B.Force the user to log out of all sessions
- ✓ C.Reset the user's password and revoke the Kerberos TGT
- D.Disable the user's account in Active Directory
Why C: Resetting the compromised domain admin's password is necessary but not sufficient by itself, because a Kerberos TGT already issued to the attacker remains valid (encrypted with the KDC's krbtgt key, not the user's password) until it expires — typically up to 10 hours, renewable up to 7 days. Microsoft does not provide a live 'revoke this one TGT' admin command; real-world options to force faster invalidation include disabling then re-enabling the account (which increments values Windows checks during the periodic account-revocation recheck), or in a severe compromise, resetting the krbtgt account password twice (which invalidates ALL TGTs domain-wide, not just this one — a drastic, disruptive step usually reserved for full domain-compromise scenarios like Golden Ticket recovery). The core lesson — a password reset alone doesn't kill an already-issued TGT — is valid; the named tool for doing so is not.
Variation 2. Your organization uses Microsoft Sentinel and Microsoft Defender XDR. An incident is generated for a user who received a phishing email that bypassed Exchange Online Protection. The user clicked the link and entered credentials on a fake login page. The incident includes alerts from Microsoft Defender for Office 365 and Microsoft Entra ID. You need to respond to the incident. The affected user has administrative privileges. Which of the following should you do FIRST?
easy- ✓ A.Reset the user's password and revoke sessions in Microsoft Entra ID.
- B.Report the phishing email to Microsoft for analysis.
- C.Create a transport rule to block similar phishing emails.
- D.Delete the phishing email from the user's mailbox.
Why A: Resetting the user's password and revoking sessions immediately prevents attacker use of stolen credentials, especially given the user has administrative privileges. Option B is wrong because reporting the email is not the highest priority. Option C is wrong because creating a transport rule is a longer-term action. Option D is wrong because deleting the email does not address the compromised credentials.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.