SC-200 Manage a security operations environment Practice Question
Which THREE are valid incident classification options in Microsoft Sentinel?
⚠ Common exam trap
Many candidates confuse alert severity levels (like Informational, Low, Medium, High) with incident classification options, leading them to incorrectly select 'Informational' as a valid classification when it is actually a severity label for alerts, not a post-investigation classification for incidents.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Benign Positive
(Benign Positive) is correct because Microsoft Sentinel uses incident classification to categorize the outcome of an investigation. A Benign Positive indicates that an alert is triggered by legitimate activity that is expected or acceptable, such as a security tool scanning the network or a user performing an authorized administrative task. This classification helps analysts distinguish between true threats and harmless events without marking them as false positives.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Informational
Why it's wrong here
Informational is not a valid incident classification in Microsoft Sentinel's classification workflow. It is one of the severity levels assigned to incidents, not a disposition label. The classification menu restricts analysts to True Positive, False Positive, and Benign Positive (with True Positive sub-classifications). Mixing severity with classification creates confusion because severity conveys urgency and impact, while classification conveys whether the alert was legitimate or erroneous.
- ✓
Benign Positive
Why this is correct
Benign Positive is a valid top-level classification in Microsoft Sentinel for activity that is confirmed to be real and potentially interesting but not malicious. Examples include a security tool triggered by an authorized penetration test, a misconfigured internal application, or a user performing an unusual but permitted action. Analysts select this classification to document harmless-but-noteworthy alerts separately from actual threats and false alarms.
- ✗
Malicious
Why it's wrong here
Malicious is not a top-level classification; it is a sub-classification that only becomes available after an incident is classified as a True Positive. In Microsoft Sentinel, an analyst first selects True Positive and may then choose a sub-classification such as Malicious, Security Test, or Unexpected to add context. Selecting Malicious without first setting True Positive is invalid because the classification schema requires the higher-level disposition to be established.
- ✓
False Positive
Why this is correct
False Positive is a valid incident classification in Microsoft Sentinel used when an alert is determined to be triggered by non-malicious, expected, or otherwise non-indicative activity. This could result from an overly broad analytic rule, a misconfigured connector, or environmental noise. It is distinct from Benign Positive because a false positive typically indicates a rule or logic issue that should be tuned, whereas a benign positive is a real security event that is simply not hostile.
- ✓
True Positive
Why this is correct
True Positive is a valid incident classification in Microsoft Sentinel used when an analyst confirms that an alert accurately identifies malicious or unauthorized activity. It serves as the primary disposition for confirmed security incidents and can be refined with sub-classifications like Malicious or Security Test to preserve details. Marking an incident as True Positive enables appropriate response actions, supports metrics, and helps validate the effectiveness of detection rules.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.