SC-200 Respond to security incidents Practice Question
An incident in Microsoft Sentinel was assigned to you. After investigation, you determine it is a false positive. What should you do to resolve the incident?
⚠ Common exam trap
Many exam-takers think they can delete an incident to remove it from the queue, but Microsoft Sentinel does not allow deletion—only closure with a proper classification is supported.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Close the incident with classification 'FalsePositive'
In Microsoft Sentinel, when an incident is determined to be a false positive, the correct resolution is to close it with the classification 'FalsePositive'. This action properly documents the outcome, updates the incident status to 'Closed', and ensures the incident is tracked for reporting and analytics. Leaving it open or changing status to 'Active' does not resolve it, while deleting is not supported and reassignment does not address the determination.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Add a comment and leave it open
Why it's wrong here
Adding a comment without closing the incident leaves the record in an unresolved state, keeping it in the active incident queue and inflating SOC metrics such as mean time to resolve. In Microsoft Sentinel, a comment only captures additional context or communication; it does not change the incident status or record an outcome classification, so the incident remains actionable and continues to consume analyst attention.
- ✓
Close the incident with classification 'FalsePositive'
Why this is correct
Closing the incident with the classification 'FalsePositive' is the correct remediation because it formally resolves the incident, records that the detected activity was not malicious, and preserves the audit trail. In Microsoft Sentinel, this action updates the incident status to 'Resolved', stores the classification and closing reason in the incident record, and can trigger automation or analytics rule tuning to reduce future false positives.
- ✗
Delete the incident
Why it's wrong here
Deleting the incident is incorrect because it removes the record entirely, destroying the evidence chain and audit history required for post-incident review, compliance, and threat hunting. Microsoft Sentinel does not treat deletion as a resolution action; incidents should be closed with a classification to retain the metadata and ensure that reporting and forensic analysis remain intact.
- ✗
Reassign to another analyst
Why it's wrong here
Reassigning the incident to another analyst only changes the owner or assignee and does not advance the incident toward resolution. Since the investigation has already determined the incident is a false positive, reassignment would needlessly duplicate effort, delay closure, and waste another analyst's time without altering the status or recording the final verdict.
- ✗
Change the status to 'Active'
Why it's wrong here
Changing the status to 'Active' is a no-op in this scenario because the incident was already active and assigned to you for investigation. The correct resolution path is to move the incident to 'Resolved' with a classification; setting it to 'Active' again leaves the lifecycle unchanged, perpetuating the open incident and failing to document the false positive finding.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.