SC-200 Respond to security incidents Practice Question
Your organization uses Microsoft Sentinel. You are responsible for responding to incidents. A new 'MFA Denied' incident is created from Microsoft Entra ID sign-in logs, indicating that a user in your organization had multiple MFA denials from a suspicious IP address (203.0.113.5). The user is a sales representative who frequently travels. The incident severity is Medium. The incident contains entities: user 'jsmith@contoso.com', IP address 203.0.113.5, and a device running Windows 11. You need to investigate and determine if this is a true positive. The user is currently on a business trip in Europe, but the sign-in attempts originated from an IP address in a different region. What should you do first?
⚠ Common exam trap
SC-200 often tests incident response order; candidates may jump to containment actions without first verifying the incident, leading to unnecessary disruption.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Contact the user to confirm if they attempted to sign in at the time of the alerts.
The first step in investigating a potential true positive is to contact the user to confirm if they attempted to sign in. This helps determine if the MFA denials were legitimate (e.g., user error) or malicious. It is a non-destructive action that gathers critical context.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Immediately reset the user's password and revoke sessions.
Why it's wrong here
Immediately resetting the user's password and revoking sessions is a high-impact containment action that should only be taken after confirming a compromise. In this scenario, the alerts indicate sign-in denials, which are commonly caused by forgotten passwords, expired credentials, or accidental lockouts — not necessarily an attacker. Acting prematurely could lock out the user and disrupt productivity, and may also destroy potential forensic evidence needed for a proper investigation. A measured triage confirms the activity is actually malicious before applying such drastic measures.
- ✓
Contact the user to confirm if they attempted to sign in at the time of the alerts.
Why this is correct
Contacting the user to confirm if they attempted to sign in is the correct initial triage step. In Microsoft Sentinel, sign-in logs and failed attempts are often false positives triggered by user behavior, such as using a personal device or mistyping a password. This direct verification helps the analyst correlate the alert with the user's actual activity, geographic location, and device, enabling a risk-based decision without causing unnecessary disruption. It aligns with standard incident response procedures that emphasize validation before containment.
- ✗
Block the suspicious IP address in the Conditional Access policy.
Why it's wrong here
Blocking the suspicious IP address in a Conditional Access policy is premature because the IP may be shared, dynamic, or used by many legitimate users in the organization. A malicious or compromised source is not yet confirmed, and creating a blanket IP block could inadvertently deny access to valid users behind a NAT or public Wi-Fi, causing a DoS situation. Additionally, attackers frequently rotate IPs, making the block ineffective while still impacting business operations. The correct approach is to first confirm intent via user validation and then, if deemed malicious, apply a targeted conditional access policy or investigate further.
- ✗
Isolate the user's device using Microsoft Defender for Endpoint.
Why it's wrong here
Isolating the user's device using Microsoft Defender for Endpoint is an endpoint-level response action intended for confirmed malware infections or active compromise of the device. The alerts described are identity-based sign-in failures, which do not necessarily indicate that the device itself is compromised, and isolation would terminate all connectivity, severely impacting productivity. Without artifacts such as suspicious processes or forensic evidence linking the device to an attack, this action is disproportionate and should be deferred until a real threat is identified.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.