Courseiva

SC-200 Respond to security incidents Practice Question

Your organization uses Microsoft Sentinel and has enabled User and Entity Behavior Analytics (UEBA). During an incident investigation, you identify that a user account has been exhibiting anomalous behavior, such as logging in from multiple countries within a short time. You need to determine if the account is compromised and take appropriate action. What should you do first?

⚠ Common exam trap

SC-200 often tests the investigate-before-remediate principle, luring candidates into picking immediate containment actions (disable, reset) instead of first validating the anomaly with UEBA context.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Review the UEBA insights for the user to understand the anomaly.

Before taking any disruptive action like disabling an account or resetting a password, the analyst must review the UEBA insights to validate whether the anomaly is a true compromise or a false positive (e.g., VPN usage, travel, or shared credentials). UEBA in Microsoft Sentinel correlates sign-in logs, Azure Activity, and other sources to surface risk scores and anomalous entities, giving the context needed for an informed decision.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Disable the user account in Microsoft Entra ID.

    Why it's wrong here

    Immediately disabling the account in Microsoft Entra ID is a premature containment action. Until you examine UEBA-driven evidence—such as risk score, anomalous sign-in patterns, or peer comparison—you cannot distinguish a true account compromise from a false-positive anomaly. An unnecessary disable can lock out a legitimate user and disrupt business operations, so this is not the correct first step in the investigation.

  • ✓

    Review the UEBA insights for the user to understand the anomaly.

    Why this is correct

    Reviewing the user's UEBA insights is the initial investigative step because Sentinel's UEBA engine has already modeled that user's historical behavior and established a baseline. These insights reveal what made the activity anomalous—for example, unexpected geo-location, new device, unusual hour, or abnormal access frequency—and provide a context-rich timeline for triage. This assessment lets the analyst validate the alert and decide on containment versus false positive before any corrective action is taken.

  • ✗

    Create a custom automation rule in Sentinel to disable the account on similar alerts.

    Why it's wrong here

    Creating a custom automation rule to disable the account on similar alerts is an operational-response playbook, not a first-step investigation activity. It presumes the anomaly is definitively malicious and generalizes a single event into a repeatable action, which risks auto-locking many legitimate users on low-fidelity or noisy alerts. Also, automation rules should be designed after an investigation has identified a reliable pattern, not triggered before confirming the current alert's validity.

  • ✗

    Reset the user's password immediately.

    Why it's wrong here

    Resetting the password immediately treats the symptom (potential credential access) without first analyzing the UEBA anomaly that fired the alert, and it bypasses the need to establish whether the activity actually came from the genuine user. Additionally, an unplanned forced reset can interrupt an active session, destroy forensic evidence in sign-in/activity logs, and is ineffective against non-credential behaviors such as data exfiltration or lateral movement that UEBA may be indicating. The appropriate sequence is to investigate the UEBA insights, corroborate the risk, and only then initiate credential remediation.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.