SC-200 Practice Question 3762

Exam: SC-200
Domain: Respond to security incidents
Difficulty: medium
You are investigating an incident involving a malicious OAuth enterprise application in Microsoft Entra ID that gained consent to read all user mailboxes. What action should the analyst take to revoke its access?

Answer Options

A
Disable sign-ins, delete Service Principal, and revoke granted OAuth permissions
B
Reboot all corporate user laptops
C
Change the domain registrar DNS nameservers
D
Format the Azure SQL database

Correct Answer

A: Disable sign-ins, delete Service Principal, and revoke granted OAuth permissions

Explanation

Disable user sign-ins on the Enterprise Application, delete the Service Principal, and revoke all granted tenant-wide OAuth admin consent permissions.