Courseiva

First Step When Reviewing a Security Alert

Exhibit

Refer to the exhibit.
```
DeviceName: DESKTOP-ABC123
AlertTime: 2025-03-01T14:32:00Z
AlertTitle: Malware detected
Severity: High
Status: Active
```

Refer to the exhibit. You are reviewing an alert in Microsoft Defender for Endpoint. The alert details are shown. Which of the following actions should you take first?

Quick Answer

The answer is to investigate the device and the alert details first. This is the correct first step when reviewing a security alert in Microsoft Defender for Endpoint because the primary goal is to understand the scope and validity of the threat before taking any disruptive action. Initiating isolation or running a scan without investigation risks alert fatigue or unnecessary system downtime, while marking an alert as a false positive requires evidence gathered during the investigation. On the Microsoft Security Operations Analyst SC-200 exam, this concept tests your understanding of the incident response lifecycle, specifically the triage phase, where analysis precedes containment. A common trap is jumping to remediation actions like isolation, but the exam emphasizes that investigation is the foundational step to avoid misconfiguration or missed lateral movement. Remember the mnemonic “Investigate Before You Isolate” to keep the correct sequence clear.

⚠ Common exam trap

The trap here is that candidates often jump to containment (isolation) or remediation (scan) because they think speed is critical, but the SC-200 exam emphasizes that investigation must always come first to avoid disrupting business operations or misclassifying alerts.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Investigate the device and the alert details

The first step in incident response is to investigate the alert details and the affected device to understand the scope and severity of the threat. Without investigation, you cannot determine whether the alert is a true positive, whether isolation is appropriate, or which remediation steps are needed. Microsoft Defender for Endpoint provides a rich investigation experience, including the alert story, device timeline, and related events, which must be reviewed before taking any containment or remediation actions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Investigate the device and the alert details

    Why this is correct

    Before containing or remediating, you must establish scope and impact. Reviewing the device timeline and alert details reveals the affected processes, files and network connections, ensuring subsequent response actions target the actual threat rather than disrupting legitimate activity.

  • ✗

    Mark the alert as a false positive

    Why it's wrong here

    Marking the alert as a false positive closes it without investigation, which is premature when the exhibit shows indicators of genuine compromise. It is tempting because it clears the queue quickly, but false-positive classification is only correct after evidence confirms benign activity, not as an initial triage action.

  • ✗

    Initiate device isolation to contain the threat

    Why it's wrong here

    Isolation is a containment action, not the first investigative step. It is tempting because containing an active threat feels urgent, but isolating before scoping the alert can disrupt business operations and destroy volatile evidence. The analyst should first review the alert details and gather context to confirm the threat.

  • ✗

    Run a full antivirus scan on the device

    Why it's wrong here

    A full antivirus scan is a remediation step, not the immediate containment action an active alert demands. It is tempting because scanning can detect additional malware, but it leaves the compromised device communicating with the network. Isolation, which severs that communication, must precede any scan.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SC-200

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A security analyst receives an alert from Microsoft Defender for Identity about a suspicious Kerberos ticket request. What is the first step the analyst should take?

easy
  • A.Disable the user account
  • B.Reset the user's password
  • C.Run a full antivirus scan on the user's device
  • ✓ D.Validate the alert by checking the user's recent activity

Why D: When Microsoft Defender for Identity alerts on a suspicious Kerberos ticket request, the first step is to validate the alert by checking the user's recent activity. This ensures the alert is not a false positive caused by legitimate behavior (e.g., scheduled tasks or application service tickets) before taking any disruptive action. Defender for Identity uses network traffic and event logs to detect anomalies like overpass-the-hash or Kerberoasting, but initial validation prevents unnecessary account lockouts or password resets.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.