SC-200 - Respond to Security Incidents - Section 2.2

Investigate and remediate identity and cloud app risks using Microsoft Defender for Cloud Apps, Microsoft Entra ID, and Microsoft Defender for Identity.

Investigate shadow IT and risky app behaviour using Microsoft Defender for Cloud Apps, and respond to compromised identities by reviewing risky users and risky sign-ins in Microsoft Entra ID. Correlate Microsoft Defender for Identity alerts to identify lateral movement and privilege escalation originating from on-premises Active Directory.

security risks in Microsoft Defender for Cloud Appscompromised identities in Microsoft Entra IDMicrosoft Defender for Identity alertsrisky users and sign-ins

Practice question for this objective

Free sampleRespond to Security Incidentsmedium

While triaging a Microsoft Defender XDR incident, an analyst sees a Microsoft Defender for Identity alert titled Suspected identity theft (pass-the-hash) for an on-premises service account. The analyst wants to determine whether the same account also shows elevated risk in the cloud and to review its recent risky sign-ins as part of one investigation. Which signal source should the analyst consult to assess the account's cloud identity risk?

  • AThe Microsoft Entra ID Protection risky users and risky sign-ins reports, which surface the account's cloud risk level and the risk detections behind its recent sign-ins for the investigation. Correct
  • BThe Microsoft Defender for Identity health alerts, which report the status of the sensors and configuration so the analyst can confirm the domain controllers are sending data for the account.
  • CThe Microsoft Defender for Cloud secure score recommendations, which rate the security posture of the subscription so the analyst can judge how exposed the account's cloud resources currently are.
  • DThe Microsoft Defender for Cloud Apps app governance dashboard, which assesses the risk of registered OAuth applications so the analyst can see whether apps consented by the account are risky.
Microsoft Entra ID Protection risky users and risky sign-ins reports surface an account's cloud identity risk level and the detections behind its recent sign-ins. Cloud identity risk for a user is computed by Microsoft Entra ID Protection, which exposes it through the risky users and risky sign-ins reports. These show the account's current risk level and the individual risk detections, letting the analyst correlate the on-premises Defender for Identity alert with cloud-side risk in one investigation. Defender for Identity health alerts cover sensor status, Defender for Cloud secure score rates workload posture, and Defender for Cloud Apps app governance rates OAuth application risk, none of which report user identity risk.

Why A is correct: Microsoft Entra ID Protection is the workload that computes cloud identity risk, so its risky users and risky sign-ins reports show the account's current risk level and the detections behind its recent sign-ins, which is precisely the cloud-side view the analyst needs.

Why B is wrong: Defender for Identity health alerts report on sensor and service health rather than identity risk, so while they confirm telemetry is flowing, they tell the analyst nothing about the account's cloud risk level or its risky sign-ins.

Why C is wrong: Microsoft Defender for Cloud secure score measures the security posture of cloud workloads and subscriptions, not the risk attached to a user identity, so it cannot tell the analyst whether this specific account shows elevated sign-in risk.

Why D is wrong: App governance evaluates the risk posture of OAuth applications and their API usage, which is about app risk rather than user identity risk, so it does not provide the account's cloud risk level or its risky sign-in history.

See more SC-200 practice questions, answers explained.

More in this domain

Back to all Respond to Security Incidents objectives, or the SC-200 cert hub.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.