First Step When Reviewing a Security Alert
Exhibit
Refer to the exhibit. ``` DeviceName: DESKTOP-ABC123 AlertTime: 2025-03-01T14:32:00Z AlertTitle: Malware detected Severity: High Status: Active ```
Refer to the exhibit. You are reviewing an alert in Microsoft Defender for Endpoint. The alert details are shown. Which of the following actions should you take first?
Quick Answer
The answer is to investigate the device and the alert details first. This is the correct first step when reviewing a security alert in Microsoft Defender for Endpoint because the primary goal is to understand the scope and validity of the threat before taking any disruptive action. Initiating isolation or running a scan without investigation risks alert fatigue or unnecessary system downtime, while marking an alert as a false positive requires evidence gathered during the investigation. On the Microsoft Security Operations Analyst SC-200 exam, this concept tests your understanding of the incident response lifecycle, specifically the triage phase, where analysis precedes containment. A common trap is jumping to remediation actions like isolation, but the exam emphasizes that investigation is the foundational step to avoid misconfiguration or missed lateral movement. Remember the mnemonic “Investigate Before You Isolate” to keep the correct sequence clear.
⚠ Common exam trap
The trap here is that candidates often jump to containment (isolation) or remediation (scan) because they think speed is critical, but the SC-200 exam emphasizes that investigation must always come first to avoid disrupting business operations or misclassifying alerts.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Investigate the device and the alert details
The first step in incident response is to investigate the alert details and the affected device to understand the scope and severity of the threat. Without investigation, you cannot determine whether the alert is a true positive, whether isolation is appropriate, or which remediation steps are needed. Microsoft Defender for Endpoint provides a rich investigation experience, including the alert story, device timeline, and related events, which must be reviewed before taking any containment or remediation actions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Investigate the device and the alert details
Why this is correct
Investigation is the first step.
- ✗
Mark the alert as a false positive
Why it's wrong here
False positive requires investigation first.
- ✗
Initiate device isolation to contain the threat
Why it's wrong here
Isolation should follow investigation.
- ✗
Run a full antivirus scan on the device
Why it's wrong here
Scan is a later step.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 209 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SC-200
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A security analyst receives an alert from Microsoft Defender for Identity about a suspicious Kerberos ticket request. What is the first step the analyst should take?
easy- A.Disable the user account
- B.Reset the user's password
- C.Run a full antivirus scan on the user's device
- ✓ D.Validate the alert by checking the user's recent activity
Why D: When Microsoft Defender for Identity alerts on a suspicious Kerberos ticket request, the first step is to validate the alert by checking the user's recent activity. This ensures the alert is not a false positive caused by legitimate behavior (e.g., scheduled tasks or application service tickets) before taking any disruptive action. Defender for Identity uses network traffic and event logs to detect anomalies like overpass-the-hash or Kerberoasting, but initial validation prevents unnecessary account lockouts or password resets.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.