SC-200 Respond to security incidents • Set 10
SC-200 Respond to security incidents Practice Test 10 — 15 questions with explanations. Free, no signup.
You are a SOC analyst using Microsoft Sentinel. An incident named 'Suspicious Azure AD sign-in from anonymous IP' is assigned to you. After investigation, you determine that the sign-in was from a known corporate VPN and the user confirmed it was legitimate. The incident contains no other alerts. You need to close the incident and ensure it does not affect future analytics. What should you do?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.