Courseiva

SC-200 · topic practice

Respond to security incidents practice questions

This domain covers responding to security incidents using Microsoft Sentinel, Defender XDR, and related tools. It tests your ability to triage, investigate, contain, and remediate threats. You must know how to use incident management, automation rules, playbooks, and advanced hunting to resolve attacks like phishing, ransomware, and data exfiltration.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Respond to security incidents

What the exam tests

What to know about Respond to security incidents

You must be able to triage and remediate incidents using Microsoft Sentinel and Defender XDR. The most important thing is to correctly use automation rules and playbooks to contain threats without disrupting legitimate business operations.

Manage incidents in Microsoft 365 Defender and Microsoft Sentinel, including assignment, status, and classification.

Use advanced hunting with KQL to investigate incidents and identify affected entities.

Configure automation rules and playbooks to automate response actions like isolating devices or blocking users.

Perform remediation actions such as soft-deleting malicious emails, isolating endpoints, or revoking user sessions.

Watch out for

Common Respond to security incidents exam traps

  • ▸Confusing automation rules with playbooks: automation rules trigger playbooks but do not perform actions directly; playbooks contain the logic.
  • ▸Forgetting that Microsoft Sentinel incidents can include entities from multiple sources, requiring cross-workspace investigation.
  • ▸Assuming Defender for Office 365 automatically blocks all phishing emails; manual remediation may be needed for missed threats.

Practice set

Respond to security incidents questions

20 questions · select your answer, then reveal the explanation

Question 1hardmulti select
Read the full Ansible explanation →

Which THREE conditions must be met for Microsoft Sentinel to automatically run a playbook on an incident?

Your organization uses Microsoft Defender for Office 365. A user reports receiving a phishing email that bypassed the default policy. You need to create a custom anti-phishing policy to block similar emails in the future. What should you configure?

You deploy the above ARM template to create a scheduled analytics rule in Microsoft Sentinel. After deployment, the rule runs but never generates incidents. What is the MOST likely cause?

Exhibit

Refer to the exhibit.

```json
{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "resources": [
    {
      "type": "Microsoft.OperationalInsights/workspaces/savedSearches",
      "apiVersion": "2020-08-01",
      "name": "[concat(parameters('workspaceName'), '/', 'MyScheduledRule')]",
      "properties": {
        "displayName": "MyScheduledRule",
        "category": "Security",
        "query": "SigninLogs | where ResultType == 50057",
        "etag": "*"
      }
    },
    {
      "type": "Microsoft.SecurityInsights/alertRules",
      "apiVersion": "2022-11-01",
      "name": "[concat(parameters('workspaceName'), '/', 'MyAlertRule')]",
      "properties": {
        "displayName": "MyAlertRule",
        "description": "Detects disabled account sign-ins",
        "severity": "Medium",
        "enabled": true,
        "query": "SigninLogs | where ResultType == 50057",
        "queryFrequency": "PT1H",
        "queryPeriod": "PT1H",
        "triggerOperator": "GreaterThan",
        "triggerThreshold": 0,
        "suppressionDuration": "PT1H",
        "suppressionEnabled": false,
        "incidentConfiguration": {
          "createIncident": true,
          "groupingConfiguration": null
        }
      }
    }
  ]
}
```

You are responding to a data exfiltration incident in Microsoft Sentinel. The attacker used a PowerShell script to upload data to an external storage account. You need to identify the specific storage account used. Which KQL query should you use in the AzureActivity table?

Which TWO actions are valid for containing a compromised user account in Microsoft 365 Defender? (Choose two.)

Which TWO Microsoft 365 Defender portals provide automated investigation and response capabilities? (Choose two.)

Question 7easymultiple choice
Read the full Ansible explanation →

Which Microsoft Sentinel feature allows you to automatically respond to incidents by running a playbook when an incident is created?

During an incident response, you identify that a user's account was used to sign in from an unusual location. You need to contain the incident immediately. What should you do first?

Question 9hardmultiple choice
Read the full Ansible explanation →

You are reviewing an automation rule in Microsoft Sentinel. The rule triggers on incident creation with severity High. However, during a recent High severity incident, the playbook did not run. What is the most likely cause?

Exhibit

Refer to the exhibit.

```json
{
  "type": "Microsoft.SecurityInsights/automationRules",
  "apiVersion": "2023-02-01-preview",
  "properties": {
    "displayName": "Contain Malicious IP",
    "order": 1,
    "triggeringLogic": {
      "triggersOn": "Incidents",
      "triggersWhen": "Created",
      "conditions": [
        {
          "property": "IncidentSeverity",
          "operator": "Equals",
          "value": "High"
        }
      ]
    },
    "actions": [
      {
        "order": 1,
        "actionType": "RunPlaybook",
        "actionConfiguration": {
          "logicAppResourceId": "/subscriptions/.../blockIP",
          "tenantId": "..."
        }
      }
    ]
  }
}
```

Which TWO are valid incident response actions in Microsoft Sentinel?

Which THREE are valid ways to automatically respond to a security incident in Microsoft Defender XDR?

Your organization uses Microsoft Defender for Identity. You receive an alert about a suspicious Kerberos authentication attempt. What is the best first step to contain the potential threat?

During a ransomware incident, you need to prevent the encryption of files on a server running Windows Server 2022. You have Microsoft Defender for Endpoint Plan 2. Which attack surface reduction rule should you enable?

Which TWO actions can be performed using Microsoft Sentinel's automation rules? (Choose two.)

Which THREE are valid containment actions in Microsoft Defender for Endpoint? (Choose three.)

Your organization uses Microsoft Purview to manage insider risk. A user is suspected of exfiltrating data via email. The incident response team needs to preserve a copy of the user's mailbox for legal hold. Which action should be taken?

Question 17easymultiple choice
Read the full Ansible explanation →

A security analyst in your organization receives an alert from Microsoft Defender for Cloud Apps indicating that a user has installed a third-party app with high permissions in Microsoft 365. The analyst suspects a consent phishing attack. Which playbook in Microsoft Sentinel should the analyst use to automate the investigation and remediation?

Which TWO components are required to enable automated investigation and response (AIR) in Microsoft Defender for Office 365?

Refer to the exhibit. This is a snippet from an automation rule in Microsoft Sentinel. What is the purpose of the 'RunQuery' action?

Exhibit

Refer to the exhibit.
```json
{
  "properties": {
    "displayName": "Investigate-Suspicious-Signin",
    "triggers": [
      {
        "type": "SentinelIncident",
        "conditions": [
          {
            "condition": "AlertName",
            "operator": "Equals",
            "value": "Suspicious sign-in activity"
          }
        ]
      }
    ],
    "actions": [
      {
        "type": "RunQuery",
        "query": "SigninLogs | where UserPrincipalName == @{trigger().outputs?.Incident?.Entities[0]?.UserPrincipalName}"
      }
    ]
  }
}
```
Question 20mediummultiple choice
Read the full Ansible explanation →

Your organization uses Microsoft Sentinel. A security analyst reports that an incident was automatically closed by a playbook before the investigation was complete. What should you do to prevent automatic closure in the future?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Respond to security incidents sessions

Start a Respond to security incidents only practice session

Every question in these sessions is drawn from the Respond to security incidents domain — nothing else.

Related practice questions

Related SC-200 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the SC-200 exam test about Respond to security incidents?
You must be able to triage and remediate incidents using Microsoft Sentinel and Defender XDR. The most important thing is to correctly use automation rules and playbooks to contain threats without disrupting legitimate business operations.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Respond to security incidents questions in a focused session?
Yes — the session launcher on this page draws every question from the Respond to security incidents domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other SC-200 topics?
Use the topic links above to move to related areas, or go back to the SC-200 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the SC-200 exam covers. They are not copied from any real exam or dump site.