SC-200 Respond to security incidents Practice Question
Your organization uses Microsoft Sentinel with UEBA (User and Entity Behavior Analytics). An alert indicates a user's sign-in from an unusual location, followed by a mass download of sensitive files from SharePoint. The user is a low-privilege employee. What is the most likely conclusion?
⚠ Common exam trap
SC-200 often tests the distinction between insider threat and external compromise — the trap is choosing 'insider threat' because the account is legitimate, ignoring that the anomalous geography points to stolen credentials rather than a trusted user acting maliciously.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The user's account is compromised
The combination of an unusual-location sign-in followed immediately by mass SharePoint downloads from a low-privilege account is the classic UEBA signature of credential compromise: an attacker authenticates with stolen credentials and exfiltrates data the account can reach. A low-privilege user has no legitimate business reason to suddenly download large volumes of sensitive files from a new geography, so the behavior deviates sharply from the account's established baseline. Microsoft Sentinel's UEBA correlates the anomalous sign-in with the abnormal data-access activity to surface this as a high-confidence compromise indicator.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The user's account is compromised
Why this is correct
In Sentinel UEBA, this alert likely combines an impossible-travel event (source IP geolocation far from the user's normal base) with a mass-download anomaly such as copying hundreds of sensitive files from SharePoint Online or OneDrive within minutes. Because the location shift coincides with a sudden spike in data access that does not match the user's established behavioral baseline, the most probable scenario is an attacker using stolen credentials. UEBA also assigns a high risk score when the anomalous activity targets sensitive data categories, and the combination of geographic and volumetric deviations strongly indicates account compromise rather than benign behavior.
- ✗
The alert is a false positive due to user travel
Why it's wrong here
A false positive from travel would explain only the location-based anomaly, not the simultaneous mass download of sensitive files. During legitimate travel, users may log in from a new IP or country but do not typically enumerate and download entire document libraries or databases, especially at non-standard times. Sentinel UEBA's 'impossible travel' detection also considers the time differential between two sign-ins, so if the account signed in at the home office and then in a distant country within minutes, even genuine travel cannot account for that. Therefore, the data-exfiltration signal disproves the simple travel false positive.
- ✗
The user is an insider threat
Why it's wrong here
While insider threat remains a theoretical possibility, the sudden deviation from the user's established behavior—particularly the anomalous geo-location—points more strongly to external credential compromise than to a malicious internal actor. A true insider would more likely operate from a known corporate network, using their own endpoint, and would not need to bypass normal access patterns with a different country source IP. UEBA's baseline includes not just what files the user accesses but also how, when, and from where, so an insider acting on their own account would rarely produce the same impossible-travel signal. Thus, without additional context like motive or a history of grievances, compromise is the higher-probability hypothesis.
- ✗
The user is conducting a ransomware attack
Why it's wrong here
A ransomware attack typically manifests as a cascade of file encryption operations—renaming files, writing encrypted versions, deleting shadow copies, and dropping a ransom note—not as a single-phase mass download of existing documents. Sentinel UEBA would generate this alert on data access and exfiltration patterns, and ransomware's destructive file modifications would appear as different event types, such as file content changes and deletion of volume shadow snapshots. Moreover, an attacker conducting ransomware would more likely use C2 activity and encryption, whereas this alert's focus on anomalous location and sensitive-data access is characteristic of a data thief using compromised credentials. Therefore, classifying the alert as ransomware is not supported by the described telemetry.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.