Courseiva
Respond to security incidentseasyMultiple ChoiceObjective-mapped

First Step When Reviewing a Security Alert

Exhibit

Refer to the exhibit.
```
DeviceName: DESKTOP-ABC123
AlertTime: 2025-03-01T14:32:00Z
AlertTitle: Malware detected
Severity: High
Status: Active
```

Refer to the exhibit. You are reviewing an alert in Microsoft Defender for Endpoint. The alert details are shown. Which of the following actions should you take first?

Quick Answer

The answer is to investigate the device and the alert details first. This is the correct first step when reviewing a security alert in Microsoft Defender for Endpoint because the primary goal is to understand the scope and validity of the threat before taking any disruptive action. Initiating isolation or running a scan without investigation risks alert fatigue or unnecessary system downtime, while marking an alert as a false positive requires evidence gathered during the investigation. On the Microsoft Security Operations Analyst SC-200 exam, this concept tests your understanding of the incident response lifecycle, specifically the triage phase, where analysis precedes containment. A common trap is jumping to remediation actions like isolation, but the exam emphasizes that investigation is the foundational step to avoid misconfiguration or missed lateral movement. Remember the mnemonic “Investigate Before You Isolate” to keep the correct sequence clear.

⚠ Common exam trap

The trap here is that candidates often jump to containment (isolation) or remediation (scan) because they think speed is critical, but the SC-200 exam emphasizes that investigation must always come first to avoid disrupting business operations or misclassifying alerts.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Investigate the device and the alert details

The first step in incident response is to investigate the alert details and the affected device to understand the scope and severity of the threat. Without investigation, you cannot determine whether the alert is a true positive, whether isolation is appropriate, or which remediation steps are needed. Microsoft Defender for Endpoint provides a rich investigation experience, including the alert story, device timeline, and related events, which must be reviewed before taking any containment or remediation actions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Investigate the device and the alert details

    Why this is correct

    Investigation is the first step.

  • Mark the alert as a false positive

    Why it's wrong here

    False positive requires investigation first.

  • Initiate device isolation to contain the threat

    Why it's wrong here

    Isolation should follow investigation.

  • Run a full antivirus scan on the device

    Why it's wrong here

    Scan is a later step.

About these practice questions

Courseiva writes every SC-200 question from scratch — 209 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SC-200

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A security analyst receives an alert from Microsoft Defender for Identity about a suspicious Kerberos ticket request. What is the first step the analyst should take?

easy
  • A.Disable the user account
  • B.Reset the user's password
  • C.Run a full antivirus scan on the user's device
  • D.Validate the alert by checking the user's recent activity

Why D: When Microsoft Defender for Identity alerts on a suspicious Kerberos ticket request, the first step is to validate the alert by checking the user's recent activity. This ensures the alert is not a false positive caused by legitimate behavior (e.g., scheduled tasks or application service tickets) before taking any disruptive action. Defender for Identity uses network traffic and event logs to detect anomalies like overpass-the-hash or Kerberoasting, but initial validation prevents unnecessary account lockouts or password resets.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.