Courseiva

SC-200 Respond to security incidents Practice Question

A SOC analyst is triaging an incident in Microsoft Sentinel and needs to assign it to a senior analyst for further investigation. What is the correct action?

⚠ Common exam trap

The trap here is that candidates might confuse external notification (email) or informal tagging (comments) with the formal ownership change required by Sentinel's incident management model, leading them to choose options that do not actually reassign the incident.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Open the incident and change the Owner field to the senior analyst.

In Microsoft Sentinel, the correct way to assign an incident to a specific analyst is to open the incident and change the Owner field to that analyst. This action formally transfers ownership and responsibility for the incident within the SIEM, ensuring proper tracking and accountability. Other methods, such as adding comments or sending emails, do not update the incident's ownership metadata.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a new incident and manually add the senior analyst as a comment.

    Why it's wrong here

    Creating a new incident in Microsoft Sentinel generates a separate incident ID and breaks the investigation's logical continuity, duplicating alerts, entities, and timeline. Adding the senior analyst as a comment merely appends text to the new incident's discussion thread; it does not set the Owner property, which is the only field that controls incident assignment. This results in two unlinked incidents, splitting the audit trail and potentially creating confusion about which incident is authoritative.

  • ✓

    Open the incident and change the Owner field to the senior analyst.

    Why this is correct

    In Microsoft Sentinel, incident ownership is controlled by the Owner field in the incident details pane; setting it to the senior analyst formally assigns the incident to them, making it appear in their 'My incidents' view and routing any notifications according to the workspace's settings. Updating the owner preserves the incident's original ID, entity links, evidence, and full audit history, which is critical for accurate incident response documentation. This action is the recommended way to escalate an incident for additional review.

  • ✗

    Close the incident and reopen it under the senior analyst's name.

    Why it's wrong here

    Closing an incident in Sentinel changes its status to Closed, which is intended for resolved or mitigated incidents and immediately triggers classification and closure metrics used in reporting. Reopening it does not offer any mechanism to reassign ownership; the Owner field would remain unchanged, and the incident would still be associated with the original analyst. This workflow corrupts closure metrics, adds unnecessary status churn, and fails to perform the actual assignment, making it both incorrect and operationally harmful.

  • ✗

    Run a playbook that sends an email to the senior analyst.

    Why it's wrong here

    Running a playbook that sends an email to the senior analyst only creates a message notification; it has no effect on the incident's Owner property, which is the authoritative attribute for assignment in Sentinel. For a playbook to reassign ownership it must use the 'Update incident' action with the Owner field set, and simply triggering a message keeps the current owner unchanged. Email also does not update the incident's audit history or UI, so the analyst would have to manually change the owner anyway.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.