SC-200 - Respond to Security Incidents (37% of the exam) - Section 2.2

Investigate and remediate identity and cloud app risks using Microsoft Defender for Cloud Apps, Microsoft Entra ID, and Microsoft Defender for Identity.

Investigate shadow IT and risky app behaviour using Microsoft Defender for Cloud Apps, and respond to compromised identities by reviewing risky users and risky sign-ins in Microsoft Entra ID. Correlate Microsoft Defender for Identity alerts to identify lateral movement and privilege escalation originating from on-premises Active Directory.

security risks in Microsoft Defender for Cloud Appscompromised identities in Microsoft Entra IDMicrosoft Defender for Identity alertsrisky users and sign-ins

Practice question for this objective

Free sampleRespond to Security Incidentsmedium

While triaging a Microsoft Defender XDR incident, an analyst sees a Microsoft Defender for Identity alert titled Suspected identity theft (pass-the-hash) for an on-premises service account. The analyst wants to determine whether the same account also shows elevated risk in the cloud and to review its recent risky sign-ins as part of one investigation. Which signal source should the analyst consult to assess the account's cloud identity risk?

  • AThe Microsoft Entra ID Protection risky users and risky sign-ins reports, which surface the account's cloud risk level and the risk detections behind its recent sign-ins for the investigation. Correct
  • BThe Microsoft Defender for Identity health alerts, which report the status of the sensors and configuration so the analyst can confirm the domain controllers are sending data for the account.
  • CThe Microsoft Defender for Cloud secure score recommendations, which rate the security posture of the subscription so the analyst can judge how exposed the account's cloud resources currently are.
  • DThe Microsoft Defender for Cloud Apps app governance dashboard, which assesses the risk of registered OAuth applications so the analyst can see whether apps consented by the account are risky.
Microsoft Entra ID Protection risky users and risky sign-ins reports surface an account's cloud identity risk level and the detections behind its recent sign-ins. Cloud identity risk for a user is computed by Microsoft Entra ID Protection, which exposes it through the risky users and risky sign-ins reports. These show the account's current risk level and the individual risk detections, letting the analyst correlate the on-premises Defender for Identity alert with cloud-side risk in one investigation. Defender for Identity health alerts cover sensor status, Defender for Cloud secure score rates workload posture, and Defender for Cloud Apps app governance rates OAuth application risk, none of which report user identity risk.

Why A is correct: Microsoft Entra ID Protection is the workload that computes cloud identity risk, so its risky users and risky sign-ins reports show the account's current risk level and the detections behind its recent sign-ins, which is precisely the cloud-side view the analyst needs.

Why B is wrong: Defender for Identity health alerts report on sensor and service health rather than identity risk, so while they confirm telemetry is flowing, they tell the analyst nothing about the account's cloud risk level or its risky sign-ins.

Why C is wrong: Microsoft Defender for Cloud secure score measures the security posture of cloud workloads and subscriptions, not the risk attached to a user identity, so it cannot tell the analyst whether this specific account shows elevated sign-in risk.

Why D is wrong: App governance evaluates the risk posture of OAuth applications and their API usage, which is about app risk rather than user identity risk, so it does not provide the account's cloud risk level or its risky sign-in history.

See more SC-200 practice questions, answers explained.

Exam traps in Respond to Security Incidents

Answers that look right on this material and are not. Each one is a distractor from a different question in the SC-200 bank for this domain.

  • Microsoft Defender for Endpoint, which inspects on-premises Active Directory authentication traffic at the domain controllers to detect Pass-the-Ticket lateral movement between domain-joined servers.

    Why it is wrong: Microsoft Defender for Endpoint detects endpoint behaviours on onboarded devices, but it does not monitor domain controller authentication traffic. Pass-the-Ticket detection from DC traffic is not its signal source, so it is the wrong owner here.

  • The Microsoft Entra ID Protection risky users report, which lists the account's cloud risk detections and risk level so the analyst can see how the identity moved between the two on-premises devices.

    Why it is wrong: The risky users report covers cloud identity risk in Microsoft Entra ID Protection and is valuable for cloud sign-in risk, but it does not model on-premises Active Directory traversal, so it cannot show how the account moved laterally between domain devices.

  • Apply a session policy to the application so that uploads to it are inspected in real time and high-risk file transfers are blocked while browsing continues

    Why it is wrong: Tempting because session policies control activity in real time, but they monitor and conditionally block actions within an app rather than blocking all access to that one application outright.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.