Microsoft Security Operations Analyst Associate SC-200 Practice Question
While investigating an incident in Microsoft 365 Defender, you open the Identity page for a user who is listed in the incident. Microsoft Entra ID has marked the user's risk level as High because of leaked credentials. You need to immediately contain the threat by stopping any future sign-ins for this user until the security team can complete its investigation and perform a credential reset. Which quick action should you take first from the Microsoft 365 Defender portal?
Choosing Disable user in the Microsoft 365 Defender portal changes the user account state in Microsoft Entra ID to Disabled. A disabled account cannot obtain new access tokens, so all sign-in attempts are blocked, containing the compromise until remediation steps such as password reset can be completed.
Revoke user sessions signs the user out of current sessions but does not block new sign-ins with the same credentials.
Reset password is an important remediation step, yet the attacker could continue to authenticate until the password is actually changed; disabling the account gives you immediate containment.
Confirm user compromised only updates the investigation status-it does not itself block authentication.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What does 'Disable user' do in Microsoft Entra ID?
Open an interactive chat with Bash
What is the difference between 'Disable user' and 'Revoke user sessions'?
Open an interactive chat with Bash
Why is resetting the password not recommended first in this case?
Open an interactive chat with Bash
Microsoft Security Operations Analyst Associate SC-200
Manage incident response
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .