SC-200 Respond to security incidents Practice Question
Your organization uses Microsoft Sentinel and Microsoft Defender for Identity. An alert fires for a potential DCSync attack. The incident response team needs to immediately block the source account from performing directory replication. Which action should be taken?
⚠ Common exam trap
A common mix-up: candidates assume resetting the password is sufficient to stop an attack, but they overlook that cached Kerberos tickets or active replication sessions can persist, making immediate account disablement the only surefire way to block DCSync in real time.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Disable the account in Microsoft Entra ID (if synced) or Active Directory.
Immediately disabling the account in Microsoft Entra ID (if synced) or Active Directory is the fastest way to stop the compromised account from performing any directory replication, including DCSync attacks. DCSync abuses the domain controller's replication protocol (MS-DRSR) to request password hashes, and disabling the account blocks all Kerberos and NTLM authentication, effectively halting the attack at the source.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use Microsoft Defender for Identity to disable the account.
Why it's wrong here
Microsoft Defender for Identity (MDI) is a security monitoring solution, not a remediation tool. It detects suspicious behavior such as DCSync attempts and lateral movement, but it has no native 'disable account' action. While MDI can trigger automated response via Microsoft Sentinel playbooks or Microsoft 365 Defender, the actual account disable must be performed directly in Microsoft Entra ID or Active Directory. Therefore, relying on MDI to disable the account is ineffective for immediate containment.
- ✗
Reset the account password and enforce a sign-out.
Why it's wrong here
Resetting the account password and forcing a sign-out does not revoke existing Kerberos tickets. A user who has already been issued a ticket-granting ticket (TGT) or service tickets can continue to use them until they expire, even after a password change. Since DCSync attacks leverage the account's replication rights rather than a stored password, password reset may not stop an in-progress credential harvesting effort. Disabling the account is the only way to immediately invalidate the account's ability to authenticate.
- ✓
Disable the account in Microsoft Entra ID (if synced) or Active Directory.
Why this is correct
Disabling the account in Microsoft Entra ID (for cloud-only accounts) or Active Directory (for on-premises or hybrid accounts) is the definitive containment step. For a hybrid environment, you should disable the account on-premises first, as Microsoft Entra Connect will synchronize the disabled state to Entra ID; for a cloud-only account, you can disable sign-in in Entra ID. This immediately prevents any new authentication attempts, including Kerberos, NTLM, or interactive logon, and blocks DCSync because the account can no longer request a TGT or authorize replication. This is the only option that fully neutralizes the compromised account.
- ✗
Remove the account from the Domain Admins group.
Why it's wrong here
Removing the account from the Domain Admins group reduces its assigned administrative privileges, but it does not guarantee the account lacks DCSync rights. DCSync (performing directory replication) is authorized through 'Replicating Directory Changes' and 'Replicating Directory Changes All' permissions, which can be granted directly on the domain naming context or inherited via other groups or delegated access. Additionally, the account remains enabled and could still be used for reconnaissance or other malicious activities. The account must be disabled to reliably stop the attack.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.