Courseiva
mediumMatching

SC-200 Practice Question: Match each incident severity level to its…

Match each incident severity level to its description in Microsoft 365 Defender.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

No impact, but may indicate an issue

Minimal impact, likely false positive

Potential impact, requires investigation

Significant impact, immediate action needed

Widespread impact, urgent response required

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Informational: Not considered malicious but may provide visibility into the environment.

Severity levels in Microsoft 365 Defender help prioritize incident response. Informational provides visibility, Low indicates minor issues, Medium requires investigation, High denotes significant threats, and Critical demands immediate action. The distractors swap or misrepresent these definitions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Informational: Not considered malicious but may provide visibility into the environment.

    Why this is correct

    Informational severity indicates events that are not inherently malicious but provide contextual awareness for security monitoring, such as reconnaissance scans or policy violations. These events may be logged for auditing or later correlation but do not represent an active threat. Because they offer visibility without confirmed compromise, no immediate response is required.

  • ✓

    Low: Minor threat or false positive; often no action needed.

    Why this is correct

    Low severity denotes activity that is suspicious but typically a false positive or minor nuisance, such as a single failed login or a low-confidence malware detection. Analysts should log it but rarely need to escalate, as the risk of actual damage is negligible. Automated triage often closes these without human intervention unless repeated patterns emerge.

  • ✓

    Medium: Threat requiring investigation; potential for damage.

    Why this is correct

    Medium severity represents a genuine threat that warrants investigation—like a known bad hash detected on one endpoint—because it could cause limited damage if left unmitigated. Analysts should review it promptly to determine if further spread occurred, but it does not require the immediate response of a high or critical incident. This level often triggers a formal incident response process.

  • ✗

    High: Minimal impact; no investigation needed.

    Why it's wrong here

    High severity does not mean minimal impact; it indicates a significant threat like a full ransomware deployment or lateral movement that requires immediate action. The correct description is the opposite—high impact, not minimal. Labeling high as requiring no investigation misrepresents the urgency and would delay containment of a compromising incident.

  • ✗

    Critical: Significant threat that requires investigation; may cause damage.

    Why it's wrong here

    Critical severity describes an imminent or widespread threat, such as active compromise of multiple assets or a data breach in progress, demanding immediate response. The given description incorrectly downgrades it to 'requires investigation, may cause damage,' which actually fits medium severity. Critical incidents invoke emergency procedures, automated containment, and executive notification.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.