Courseiva

SC-200 Respond to security incidents Practice Question

Which THREE are valid investigation actions in Microsoft Sentinel? (Select THREE.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

View related entities such as IP addresses.

Viewing related entities such as IP addresses is a fundamental investigation action in Microsoft Sentinel. Option C is correct because viewing related incidents helps in correlating events. Option E is correct because viewing related alerts provides context. Option B is incorrect because running a playbook is a remediation action, not an investigation action. Option D is incorrect because modifying an analytics rule is a configuration task outside the investigation scope.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    View related entities such as IP addresses.

    Why this is correct

    Viewing related entities such as IP addresses is a core Sentinel investigation action, letting analysts pivot from an incident to the associated hosts, accounts and addresses on the entity graph. This satisfies the stem's requirement for valid investigation actions, since entity exploration is built into the incident investigation experience.

  • ✗

    Run a playbook.

    Why it's wrong here

    Playbooks are automated responses triggered by automation rules or alerts, not actions you invoke from the investigation graph against entities. Investigation actions gather evidence and act on entities. Running a playbook is correct when automating containment or notification after an incident is created.

  • ✓

    View related incidents.

    Why this is correct

    Viewing related incidents groups alerts and entities that share the same underlying activity, letting analysts pivot from one incident to correlated ones without manual hunting. This satisfies the investigation requirement by exposing the incident graph Microsoft Sentinel builds automatically, so analysts can assess scope and link separate detections to a single threat.

  • ✗

    Modify an analytics rule.

    Why it's wrong here

    Analytics rules generate alerts and incidents; they are configured under Analytics, not run against an incident during triage. Investigation actions operate on entities, evidence and the incident itself. Modifying a rule is a detection-engineering task, correct when tuning false positives or adding new threat coverage outside an active investigation.

  • ✓

    View related alerts.

    Why this is correct

    Viewing related alerts lets investigators pivot from an incident to correlated alerts sharing entities or tactics, surfacing context the incident view alone omits. This satisfies the stem's requirement for a valid Sentinel investigation action, as the incident blade exposes related alerts natively without leaving the portal.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.