SC-200 Practice Question 3763
Exam: SC-200
Domain: Respond to security incidents
Difficulty: medium
You are investigating an incident involving a malicious OAuth enterprise application in Microsoft Entra ID that gained consent to read all user mailboxes. What action should the analyst take to revoke its access?
Answer Options
A
Disable sign-ins, delete Service Principal, and revoke granted OAuth permissions
B
Reboot all corporate user laptops
C
Change the domain registrar DNS nameservers
D
Format the Azure SQL database
Correct Answer
A: Disable sign-ins, delete Service Principal, and revoke granted OAuth permissions
Explanation
Disable user sign-ins on the Enterprise Application, delete the Service Principal, and revoke all granted tenant-wide OAuth admin consent permissions.