Courseiva

SC-200 Respond to security incidents Practice Question

Your organization uses Microsoft Sentinel. A security analyst receives an alert indicating that a user account was used to sign in from an unfamiliar location. You need to investigate the incident using Microsoft Defender XDR. Which action should you take first?

⚠ Common exam trap

The trap here is that candidates often jump to immediate containment actions like password reset or account disablement, forgetting that the first step in any incident response process is to verify and classify the alert to avoid unnecessary operational impact.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Review the alert in the Microsoft Defender XDR portal and classify it as a true or false positive.

The first step in incident response is to validate the alert by reviewing it in the Microsoft Defender XDR portal. This allows the analyst to assess the alert's context, such as sign-in logs, user risk, and related entities, before taking any corrective action. Classifying the alert as a true or false positive ensures that subsequent steps (like password reset or account disablement) are based on accurate threat assessment, preventing unnecessary disruption.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create an automated playbook to reset the user's password.

    Why it's wrong here

    Automated playbooks in Microsoft Sentinel are designed for post-confirmation response actions, not initial triage. Executing a password reset before the incident is classified as a true positive can lock out an innocent user or fail to address an attacker's alternative persistence methods. The first phase of incident response in the Microsoft Defender XDR portal is validation and classification, so this remediation should be saved until after the verdict is established.

  • ✓

    Review the alert in the Microsoft Defender XDR portal and classify it as a true or false positive.

    Why this is correct

    The Microsoft Defender XDR portal is the central console for investigating alerts and incidents across the Microsoft 365 Defender suite. The first step in any incident response is to verify the alert's validity by examining the evidence, related entities, and the incident timeline. Classifying the alert as a true or false positive determines whether subsequent containment, eradication, or closure actions are necessary, making this the correct initial action.

  • ✗

    Turn off the user account in Microsoft Entra ID.

    Why it's wrong here

    Disabling a user account in Microsoft Entra ID is a containment action that presumes the alert is a true positive and that the compromised account is the only access vector. Performing this before classification can cause unnecessary productivity disruption if the alert is a false positive, and it may not stop an attacker who has already established persistence through other identities or tokens. Containment measures like account disablement are only appropriate after you have triaged the incident and confirmed the scope of compromise.

  • ✗

    Reset the user's password immediately to prevent further access.

    Why it's wrong here

    Resetting a user's password immediately is a hasty containment measure that should follow, not precede, incident classification. If the alert is a false positive, the reset is an unauthorized change to credentials that can cause access issues for a legitimate user. Furthermore, if the attacker has established persistence via a refresh token or alternate credential, resetting the password alone will not eliminate the threat; proper triage ensures the response addresses the actual attack chain.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.