SC-200 Respond to security incidents Practice Question
Your security team is investigating a suspicious sign-in from an unfamiliar IP address. The user has Microsoft Entra ID P2 licenses and is assigned a Conditional Access policy that requires MFA for all cloud apps. During the incident response, you find that the sign-in succeeded despite the user not completing MFA. Which action should you take first to investigate the discrepancy?
⚠ Common exam trap
SC-200 often tests the misconception that audit logs or risk detections are the first place to look, but the sign-in log provides the most direct evidence of why MFA was not enforced.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Review the Microsoft Entra sign-in logs for the specific sign-in event
Reviewing the Microsoft Entra sign-in logs for the specific sign-in event is the first step because it provides detailed information about the sign-in, including whether MFA was required, satisfied, or bypassed. This log will show the conditional access policy evaluation and any anomalies, helping to identify why MFA was not enforced.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Review the user risk detection in Microsoft Entra ID Protection
Why it's wrong here
Risk detections flag compromised or anomalous accounts; they do not explain why a Conditional Access MFA requirement was bypassed during a specific sign-in. Entra ID Protection risk review is the correct first step when the question concerns whether an account is compromised, not which policy logic permitted authentication.
- ✗
Check the Microsoft Entra audit logs for policy changes
Why it's wrong here
Audit logs record administrative and directory changes, not the per-sign-in Conditional Access policy evaluation results that explain why MFA was skipped. It is tempting because policy edits can cause gaps, but the sign-in log's Conditional Access tab shows which policies applied and their outcome.
- ✗
Use the Conditional Access What If tool
Why it's wrong here
What If evaluates hypothetical policy conditions against a simulated user, so it cannot replay the actual sign-in and reveal which policy applied or why MFA was skipped. It is tempting because it validates Conditional Access design before deployment, which is the right choice when planning a new policy rather than investigating a completed authentication event.
- ✓
Review the Microsoft Entra sign-in logs for the specific sign-in event
Why this is correct
The Microsoft Entra sign-in logs record which Conditional Access policies applied, whether MFA was satisfied, and the authentication method used, directly explaining why MFA was bypassed. Reviewing this event first satisfies the need to investigate the discrepancy before changing policy or revoking sessions.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.