Microsoft Security Operations Analyst Associate SC-200 Practice Question

A business email compromise (BEC) attempt was automatically disrupted and raised as an incident in Microsoft 365 Defender. In the Disruption details tab you confirm that the affected mailbox was user-contained. Which immediate containment action did Microsoft 365 Defender apply to the compromised user account during the automatic attack disruption?

  • The user's mailbox was quarantined and all existing messages were moved to the Recoverable Items folder.

  • The user's devices were automatically isolated from the network by Microsoft Defender for Endpoint.

  • The user's Microsoft 365 license was removed to prevent mailbox access.

  • The account's sign-in was blocked by setting its status to disabled in Microsoft Entra ID, immediately preventing further logons.

Microsoft Security Operations Analyst Associate SC-200
Manage incident response
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot