Microsoft Security Operations Analyst Associate SC-200 Practice Question

You receive an alert in the Microsoft Defender portal indicating that a user account has been flagged by Microsoft Entra ID Identity Protection with the risk event Leaked credentials and a user risk level of High. You determine that the credentials are compromised and want to force the user to take immediate action while ensuring the account's risk state is changed to Remediated after the user complies. In the Risky users blade of Identity Protection, which manual action should you perform on the account?

  • Dismiss the user's risk

  • Disable the user's Azure AD-joined device

  • Confirm the user as compromised

  • Require password reset for the user

Microsoft Security Operations Analyst Associate SC-200
Manage incident response
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot