SC-200 Manage a security operations environment Practice Question
Your security team uses Microsoft Defender XDR. You need to ensure that a user who is suspected of credential theft is immediately blocked from accessing corporate email and cloud apps, while the investigation continues. What should you do?
⚠ Common exam trap
Candidates often confuse 'blocking access' with 'disabling the account' or 'resetting the password,' not realizing that immediate token revocation via Defender for Cloud Apps is the only option that stops active sessions without disrupting the user's directory object.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use Microsoft Defender for Cloud Apps to suspend the user
Suspending the user in Microsoft Defender for Cloud Apps immediately revokes the user's access tokens and active sessions for cloud apps, blocking further access to corporate email and cloud apps without deleting the account. This allows the investigation to continue while the user is isolated, which is the precise requirement for a suspected credential theft scenario.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a conditional access policy in Microsoft Entra ID to block the user
Why it's wrong here
Conditional Access policies are evaluated only at authentication time when a token is requested. A policy that blocks the user will not revoke tokens that have already been issued, and it can take several minutes for the policy to propagate across Microsoft Entra ID, so an already-authenticated attacker can keep accessing applications until those existing sessions expire.
- ✓
Use Microsoft Defender for Cloud Apps to suspend the user
Why this is correct
Suspending the user in Microsoft Defender for Cloud Apps is the correct immediate response because it sends a governance action through the connected app connectors to invalidate the user’s active sessions and tokens for all connected cloud apps. This terminates ongoing access in near-real time, making it effective for containing an active compromise rather than waiting for sign-in-time controls to take effect.
- ✗
Disable the user account in Microsoft Entra ID
Why it's wrong here
Disabling the user account in Microsoft Entra ID prevents new sign-ins but does not revoke or invalidate access tokens and refresh tokens that were already issued. It also relies on directory replication and token lifetime, so active sessions may continue for minutes or even hours, which is too slow and incomplete for immediate containment during an active incident.
- ✗
Reset the user's password from Microsoft Entra ID
Why it's wrong here
Resetting the user’s password invalidates password-based authentication, but it does not revoke existing access tokens, refresh tokens, or federated session cookies. An attacker who already has a valid session or token can continue operating without needing to re-authenticate, so password reset alone fails to cut off active unauthorized access.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.