SC-200 Respond to security incidents Practice Question
In Microsoft Sentinel, an incident is created from a Fusion rule that correlates multiple alerts. The incident has a high severity. What should the analyst do first?
⚠ Common exam trap
A common mix-up: candidates assume a high-severity incident automatically requires immediate containment or escalation, but Microsoft Sentinel's incident response process mandates triage first to validate the correlation and avoid acting on false positives.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Triage the incident by reviewing the evidence
The first step in incident response within Microsoft Sentinel is to triage the incident by reviewing the evidence. A Fusion rule correlates multiple alerts into a single incident, and the analyst must examine the correlated alerts, entities, and timeline to validate the incident's legitimacy and understand the scope before taking any action. Automated playbooks or escalations should only occur after triage confirms the incident is a genuine threat.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Run an automated playbook to contain the threat
Why it's wrong here
Running an automated playbook to contain the threat immediately after Fusion generates an incident is premature because playbooks are designed to execute after an analyst has triaged the incident and confirmed its validity. Fusion correlates alerts and may produce false positives or incomplete attack narratives, so automating containment without human assessment could disrupt legitimate operations or trigger unrelated remediation. Proper order is triage, then investigate, and only then invoke playbooks for containment or other responses.
- ✗
Close the incident as false positive
Why it's wrong here
Closing the incident as a false positive without reviewing the accumulated evidence defeats the purpose of Fusion's correlation engine, which uses machine learning to identify genuine multi-stage threats. Even if the initial impression seems benign, the incident may contain underlying alerts or entities that warrant investigation. Closing without triage skips the validation step and could allow an actual attack to proceed undetected, violating standard incident response procedures.
- ✓
Triage the incident by reviewing the evidence
Why this is correct
Triage by reviewing the evidence is the mandatory first action for any Fusion-generated incident in Microsoft Sentinel, as it confirms whether the correlated alerts represent a genuine security threat and establishes the appropriate severity and priority. Analysts examine the incident's alerts, entities, and timeline to understand the attack chain and decide on next steps. This initial assessment ensures that subsequent actions—whether investigation, containment, or escalation—are based on accurate and complete information.
- ✗
Escalate the incident to senior management
Why it's wrong here
Escalating a Fusion incident directly to senior management without first triaging it is inappropriate because escalation is a communication step that should follow a validated understanding of the incident's severity, impact, and business risk. Skipping triage means the escalation lacks necessary context, often causing unnecessary alarm or being ignored as noise. In a SOC workflow, initial escalation typically goes to a supervisor or incident commander after triage, not directly to senior management.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on SC-200
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Your organization uses Microsoft Sentinel. A fusion incident was created involving multiple alerts from different sources. You need to investigate the incident to determine if it is a true positive. What is the first step you should take?
medium- A.Run a KQL query on the raw logs to see if the alerts are connected.
- B.Assign the incident to a senior analyst for further investigation.
- ✓ C.Review the incident timeline and entity mapping in the incident details.
- D.Close the incident as a false positive if the alerts seem unrelated.
Why C: The first step in investigating a Fusion incident in Microsoft Sentinel is to review the incident timeline and entity mapping. This provides a consolidated view of all correlated alerts, their timestamps, and the entities involved (e.g., IP addresses, user accounts), enabling you to quickly assess whether the alerts are logically connected and indicative of a true positive attack chain. Starting with this high-level overview is efficient before diving into raw logs.
Variation 2. Your organization uses Microsoft Sentinel. A security incident is created, and the assigned analyst needs to perform initial triage. What is the first step the analyst should take according to Microsoft best practices for incident response?
easy- A.Contain the affected resources immediately to prevent further damage.
- B.Run a full investigation using Microsoft 365 Defender hunting queries.
- ✓ C.Review the incident details and verify the alert is a true positive.
- D.Escalate the incident to the senior security team.
Why C: The first step in the Microsoft incident response process is to verify the alert and determine its validity. Option A is wrong because containment should follow after verification. Option B is wrong because escalating before verification bypasses triage. Option D is wrong because detailed investigation comes after initial triage.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.