Courseiva

SC-200 Manage a security operations environment Practice Question

Which THREE are valid incident classification options in Microsoft Sentinel?

⚠ Common exam trap

Many candidates confuse alert severity levels (like Informational, Low, Medium, High) with incident classification options, leading them to incorrectly select 'Informational' as a valid classification when it is actually a severity label for alerts, not a post-investigation classification for incidents.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Benign Positive

(Benign Positive) is correct because Microsoft Sentinel uses incident classification to categorize the outcome of an investigation. A Benign Positive indicates that an alert is triggered by legitimate activity that is expected or acceptable, such as a security tool scanning the network or a user performing an authorized administrative task. This classification helps analysts distinguish between true threats and harmless events without marking them as false positives.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Informational

    Why it's wrong here

    Informational is not a valid incident classification in Microsoft Sentinel's classification workflow. It is one of the severity levels assigned to incidents, not a disposition label. The classification menu restricts analysts to True Positive, False Positive, and Benign Positive (with True Positive sub-classifications). Mixing severity with classification creates confusion because severity conveys urgency and impact, while classification conveys whether the alert was legitimate or erroneous.

  • ✓

    Benign Positive

    Why this is correct

    Benign Positive is a valid top-level classification in Microsoft Sentinel for activity that is confirmed to be real and potentially interesting but not malicious. Examples include a security tool triggered by an authorized penetration test, a misconfigured internal application, or a user performing an unusual but permitted action. Analysts select this classification to document harmless-but-noteworthy alerts separately from actual threats and false alarms.

  • ✗

    Malicious

    Why it's wrong here

    Malicious is not a top-level classification; it is a sub-classification that only becomes available after an incident is classified as a True Positive. In Microsoft Sentinel, an analyst first selects True Positive and may then choose a sub-classification such as Malicious, Security Test, or Unexpected to add context. Selecting Malicious without first setting True Positive is invalid because the classification schema requires the higher-level disposition to be established.

  • ✓

    False Positive

    Why this is correct

    False Positive is a valid incident classification in Microsoft Sentinel used when an alert is determined to be triggered by non-malicious, expected, or otherwise non-indicative activity. This could result from an overly broad analytic rule, a misconfigured connector, or environmental noise. It is distinct from Benign Positive because a false positive typically indicates a rule or logic issue that should be tuned, whereas a benign positive is a real security event that is simply not hostile.

  • ✓

    True Positive

    Why this is correct

    True Positive is a valid incident classification in Microsoft Sentinel used when an analyst confirms that an alert accurately identifies malicious or unauthorized activity. It serves as the primary disposition for confirmed security incidents and can be refined with sub-classifications like Malicious or Security Test to preserve details. Marking an incident as True Positive enables appropriate response actions, supports metrics, and helps validate the effectiveness of detection rules.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.