Courseiva

SC-200 Respond to security incidents Practice Question

Your organization uses Microsoft Sentinel with the Microsoft 365 Defender connector. You receive an incident indicating that a user's account was used to sign in from an unusual location (Russia) while the user is in the United States. The sign-in was successful and no MFA challenge was prompted because the user had a valid session. The incident severity is High. You need to respond immediately. What should you do first?

⚠ Common exam trap

Many exam-takers choose 'Reset the user's password' thinking it kills all sessions, but in Microsoft Entra ID, password reset does not revoke existing tokens or sessions unless combined with explicit token revocation or a 'Sign out everywhere' action.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Revoke the user's session in Microsoft Entra ID.

Revoking the user's session in Microsoft Entra ID immediately terminates all active tokens and sessions, preventing the attacker from continuing to use the authenticated session. This is the fastest way to stop the ongoing compromise because the sign-in succeeded without MFA due to a valid session, and the attacker is already inside. Other actions like blocking IP or resetting password are slower or less direct in this scenario.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Block the IP address in the Conditional Access policy.

    Why it's wrong here

    Blocking the IP address in a Conditional Access policy applies only to future authentication requests and does not invalidate an already-issued session token. An active attacker with a valid token can continue accessing resources until that token expires, and many exit nodes (cloud services, VPNs) are shared or dynamic, causing the block to impact legitimate users. A sophisticated adversary can also switch to a different IP or proxy, so this is not a reliable or immediate containment step.

  • ✓

    Revoke the user's session in Microsoft Entra ID.

    Why this is correct

    Revoking the user's session in Microsoft Entra ID immediately invalidates all refresh tokens for that user and forces re-authentication across all applications, terminating the attacker's active session without waiting for token expiry. This is the correct initial response in a Sentinel incident because it stops ongoing unauthorized access at the session layer, which is faster and more comprehensive than network-level or credential-based actions. It is a precise containment step that precedes password reset and further investigation.

  • ✗

    Investigate the sign-in logs to determine if there are other compromised accounts.

    Why it's wrong here

    Investigating sign-in logs to identify other compromised accounts is a critical part of the incident response, but it is not the immediate first action when a single account is confirmed compromised. The priority is to stop the threat by revoking the active session; broadening the investigation can happen afterward without risking further attacker activity. Delaying containment while reviewing logs gives the adversary more time to move laterally, escalate privileges, or persist in the environment.

  • ✗

    Reset the user's password.

    Why it's wrong here

    Resetting the user's password stops the attacker from using the stolen credentials for future sign-ins, but it does not invalidate the session tokens the attacker already holds. Without an explicit session revocation, those tokens remain valid until they expire, allowing the attacker to continue accessing resources even after the password is changed. Therefore, a password reset alone is insufficient as an immediate containment measure; session revocation must be performed to terminate the active, token-based access.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.