Courseiva

SC-200 Manage a security operations environment Practice Question

A security incident in Microsoft Sentinel has been classified as a true positive and remediated. According to your SOC playbook, the incident should be closed with a classification of 'True Positive' and a sub-classification of 'Confirmed activity'. What is the correct way to close the incident in Microsoft Sentinel?

⚠ Common exam trap

Candidates often assume closing an incident in Microsoft Defender XDR will sync all details to Sentinel, but in reality, Sentinel requires direct closure within its own interface to apply classification and sub-classification fields.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

In the Microsoft Sentinel incident, set Status to 'Closed', Classification to 'True Positive', and Sub-classification to 'Confirmed activity'.

Using the Microsoft Security Graph API to close the incident is unnecessary and out of scope here: the scenario calls for a single incident to be manually closed per the SOC playbook's exact classification and sub-classification values, which is done directly in the Microsoft Sentinel incident pane. The Graph API is useful for bulk/programmatic incident updates, but that is not what this scenario requires, so it is not the correct choice here.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    In the Microsoft Sentinel incident, set Status to 'Closed', Classification to 'True Positive', and Sub-classification to 'Confirmed activity'.

    Why this is correct

    In the Microsoft Sentinel incident pane, set Status to 'Closed', Classification to 'True Positive', and Sub-classification to 'Confirmed activity'. This exact combination satisfies the SOC playbook's closure criteria and writes the triage verdict into the incident metadata for Microsoft Sentinel analytics and reporting. Closing directly in Sentinel ensures that any automation rules triggered by incident closure run with the expected values, preserving the audit trail for compliance.

  • ✗

    Close the incident in Microsoft Defender XDR and let it sync to Microsoft Sentinel.

    Why it's wrong here

    Closing the incident in Microsoft Defender XDR and waiting for synchronization to Microsoft Sentinel is unreliable because the Defender portal exposes only the top-level classification, such as 'True positive', and does not offer Sentinel's 'Sub-classification' field like 'Confirmed activity'. Even if the close event syncs through the unified incident integration, the playbook's required sub-classification value is not carried over, so the Sentinel incident will not match the documented closure standard. The SOC playbook explicitly calls for closure to be performed in the Sentinel UI to trigger the associated Logic App and record the correct sub-classification.

  • ✗

    Change the incident status to 'Closed' without adding a classification.

    Why it's wrong here

    Merely changing the incident status to 'Closed' without assigning a classification is non-compliant because Microsoft Sentinel treats classification as a required closing field when the workspace or the linked playbook enforces it. Without the 'True Positive' classification and 'Confirmed activity' sub-classification, the incident lands in a 'Not classified' state, and downstream security metrics such as the true-positive rate and automated reporting will silently omit this incident. The playbook is designed to validate these fields on closure, so an unclassified close will fail validation and leave the incident outside the SOC's documented process.

  • ✗

    Use the Microsoft Security Graph API to close the incident with the appropriate classification.

    Why it's wrong here

    Using the Microsoft Security Graph API to close the incident would require a custom script or automation, but the scenario demands a manual closure with the specific classification and sub-classification directly within the Microsoft Sentinel interface, as per the SOC playbook. This API is tempting because it can automate bulk incident updates, making it the correct choice for high-volume, programmatic workflows where manual interaction is impractical.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.