SC-200 Manage a security operations environment Practice Question
Your organization uses Microsoft Defender XDR and Microsoft Sentinel. You need to configure a solution that automatically blocks a user's account when a high-severity incident is generated. The solution must use built-in capabilities without custom code. What should you do?
⚠ Common exam trap
It's easy for candidates to confuse device isolation (Microsoft Defender for Endpoint) with user account blocking (Microsoft Entra ID), or incorrectly assume that conditional access policies can be triggered by external alerts, when in fact they require specific risk signals from Microsoft Entra ID Protection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an automation rule that triggers on incident creation with severity high, and runs a playbook that uses the 'Update user' action to disable the account.
Microsoft Sentinel automation rules can trigger on incident creation with a condition of severity equals high, and then run a playbook. The playbook can use the Microsoft Entra ID connector's 'Update user' action to disable the user account, which is a built-in capability requiring no custom code. This directly meets the requirement to automatically block a user's account when a high-severity incident is generated.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create an automation rule that triggers on incident creation with severity high, and runs a playbook that uses the 'Update user' action to disable the account.
Why this is correct
Automation rules in Microsoft Defender XDR can be configured to trigger immediately upon incident creation when the severity is high. The associated playbook (built on Azure Logic Apps) invokes the 'Update user' action, which calls the Microsoft Graph API to disable the specified Entra ID (Azure AD) account. This is the correct approach because it directly addresses the user account as the containment target and executes automatically without manual intervention.
- ✗
Use a scheduled analytics rule that runs every hour and disables accounts found in the results.
Why it's wrong here
Scheduled analytics rules are designed to periodically run a KQL query and generate alerts based on the results; they do not have a built-in capability to execute remediation actions such as disabling an account. While you could attach a playbook to the resulting alerts, the rule itself only creates the alert—any action would require additional workflow configuration, and the hourly cadence introduces a significant delay during which the compromised account remains active.
- ✗
Configure Microsoft Entra ID to automatically apply a conditional access policy blocking sign-ins when a high-severity alert is raised.
Why it's wrong here
Conditional Access policies in Microsoft Entra ID are evaluated during sign-in attempts based on conditions such as user risk, location, device compliance, or application, not on alert severity or incident creation. There is no native mechanism to automatically apply a blocking policy solely because a high-severity alert in Defender XDR was raised, and doing so would require custom automation or integration via the Graph API/remediation APIs, which is not a standard configuration.
- ✗
Create a playbook that uses the 'Run a query' action to find the device and then uses Microsoft Defender for Endpoint to isolate the device.
Why it's wrong here
This playbook focuses on isolating the device using Microsoft Defender for Endpoint, which is a device-level containment action—it does nothing to disable the user account itself. Even though the 'Run a query' action can identify the device associated with the alert, the requested outcome is to neutralize the user account to prevent further unauthorized access. Thus, while isolating the device may be a supplementary step, it is not the correct solution for disabling the user.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.