Microsoft Security Operations Analyst Associate SC-200 Practice Question
Automatic attack disruption in Microsoft Defender XDR has flagged a user account as compromised during an active business email compromise (BEC) incident. You must immediately stop the attacker from sending additional malicious messages while ensuring the mailbox content remains available for forensic investigation. From the Microsoft Defender portal incident page, which remediation action should you perform first?
Disable the user account in Microsoft Entra ID
Remove all malicious and suspicious inbox rules from the mailbox
Revoke all active user sessions in Microsoft Entra ID
Block the user from sending email in Exchange Online
Microsoft's incident-response guidance for BEC stresses disabling the compromised Microsoft Entra ID account as the initial containment step. Disabling sign-in instantly prevents the attacker from accessing Microsoft 365-including the ability to send further emails-while the underlying Exchange Online mailbox and its data remain intact for investigators. Blocking outbound email alone limits only one attack path and still leaves the attacker signed in. Removing inbox rules does not terminate access, and revoking sessions may leave active tokens valid for up to an hour, permitting continued abuse. Therefore, disabling the user account is the most effective first action.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Microsoft Entra ID, and why is it crucial in incident response?
Open an interactive chat with Bash
Why is disabling a user account more effective than blocking outbound email or revoking sessions?
Open an interactive chat with Bash
How does disabling a user account in Microsoft Entra ID affect forensic investigation?
Open an interactive chat with Bash
Microsoft Security Operations Analyst Associate SC-200
Manage incident response
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .