Courseiva

SC-200 Respond to security incidents Practice Question

Your organization uses Microsoft Sentinel and Microsoft Defender XDR. An incident is generated for a user who received a phishing email that bypassed Exchange Online Protection. The user clicked the link and entered credentials on a fake login page. The incident includes alerts from Microsoft Defender for Office 365 and Microsoft Entra ID. You need to respond to the incident. The affected user has administrative privileges. Which of the following should you do FIRST?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Reset the user's password and revoke sessions in Microsoft Entra ID.

Resetting the user's password and revoking sessions immediately prevents attacker use of stolen credentials, especially given the user has administrative privileges. Option B is wrong because reporting the email is not the highest priority. Option C is wrong because creating a transport rule is a longer-term action. Option D is wrong because deleting the email does not address the compromised credentials.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Reset the user's password and revoke sessions in Microsoft Entra ID.

    Why this is correct

    Because the user holds administrative privileges, credential reset alone is insufficient — active refresh tokens and sessions must be revoked in Microsoft Entra ID to evict the attacker immediately. This contains the compromised privileged identity before any further investigation, satisfying the stem's requirement to act first.

  • ✗

    Report the phishing email to Microsoft for analysis.

    Why it's wrong here

    Submitting the message to Microsoft improves future detection but takes no immediate action against the active compromise of a privileged account. It tempts because reporting is a routine analyst step, and would be correct once containment is complete and the sender infrastructure is being tracked.

  • ✗

    Create a transport rule to block similar phishing emails.

    Why it's wrong here

    A transport rule only blocks future inbound mail and does nothing about the already-compromised privileged account, leaving the attacker's access intact. It tempts because transport rules are the standard control for recurring phishing campaigns, and would be correct after the account is contained and the incident scoped.

  • ✗

    Delete the phishing email from the user's mailbox.

    Why it's wrong here

    Removing the message is containment, not the first priority: the privileged account's credentials are already compromised, so the session and password must be revoked before mailbox cleanup. It tempts because purging phishing mail is standard remediation, and would be correct once the account is secured.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.