SC-200 Respond to security incidents Practice Question
Your organization uses Microsoft Sentinel and Microsoft Defender XDR (including Defender for Endpoint, Defender for Office 365, Defender for Identity, and Defender for Cloud Apps). You have an incident response team that operates 24/7. Recently, there have been multiple incidents involving users receiving phishing emails that lead to credential theft. The phishing emails are sophisticated and bypass Exchange Online Protection (EOP) and Defender for Office 365's built-in phishing filters. The emails contain links to fake login pages that harvest credentials. Once credentials are stolen, the attacker uses them to sign in from anonymous IP addresses and attempts to access sensitive data in SharePoint Online. You need to design a response strategy that includes automated containment and investigation. The solution must: - Automatically disable user accounts when a phishing incident is confirmed. - Automatically trigger an investigation into the user's activity in Microsoft Defender for Cloud Apps. - Send a notification to the incident response team with a summary of the incident. - Minimize manual effort.
You have the following components available: - Microsoft Sentinel with automation rules and playbooks. - Microsoft Defender XDR with advanced hunting. - Microsoft Power Automate.
What is the most efficient way to achieve these requirements?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a playbook in Microsoft Sentinel that uses the Microsoft Graph API to disable the user account in Microsoft Entra ID, trigger an investigation in Microsoft Defender for Cloud Apps, and send an email notification. Associate the playbook with an automation rule that runs when the incident is created.
Creating a playbook in Microsoft Sentinel that uses the Microsoft Graph API to disable the user in Microsoft Entra ID, triggers an investigation in Defender for Cloud Apps, and sends an email notification, then associating it with an automation rule that runs automatically when the incident is created, meets all requirements with minimal manual effort. Option B is correct because it enables automated containment and investigation without manual intervention. Option A is incorrect because Microsoft Defender XDR's automated investigation and response (AIR) does not automatically disable user accounts across all services; it focuses on endpoint remediation. Option C is incorrect because relying on a third-party system via webhook introduces additional complexity and may not integrate seamlessly with Microsoft tools. Option D is incorrect because while Power Automate can be used, creating a playbook directly in Microsoft Sentinel is more tightly integrated and efficient for incident response workflows.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use Microsoft Defender XDR's automated investigation and response (AIR) to automatically disable the user account.
Why it's wrong here
AIR in Defender XDR can disable user accounts but does not trigger a separate investigation in Defender for Cloud Apps.
- ✓
Create a playbook in Microsoft Sentinel that uses the Microsoft Graph API to disable the user account in Microsoft Entra ID, trigger an investigation in Microsoft Defender for Cloud Apps, and send an email notification. Associate the playbook with an automation rule that runs when the incident is created.
Why this is correct
This fully automates containment, investigation, and notification.
- ✗
Create an automation rule in Microsoft Sentinel that triggers a webhook to a third-party system, which then disables the user account.
Why it's wrong here
This requires a third-party system and may not trigger the Defender for Cloud Apps investigation.
- ✗
Configure a Playbook in Power Automate that monitors Microsoft Sentinel incidents and automatically disables the user account.
Why it's wrong here
Power Automate is not native to Sentinel and may have delays; also lacks direct integration for Defender for Cloud Apps investigation.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.