SC-200 Respond to security incidents Practice Question
Which THREE of the following are valid incident management capabilities in Microsoft Sentinel? (Choose three.)
⚠ Common exam trap
Candidates often confuse automation (playbooks) and reporting (workbooks) with direct incident management actions, but Microsoft Sentinel explicitly separates incident management capabilities (assignment, classification, merging) from automation and visualization features in the exam blueprint.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Assign incidents to analysts or teams
A is correct because Microsoft Sentinel allows incident owners to be assigned directly to an analyst or a team via the 'Owner' field in the incident details pane. This assignment is used for tracking responsibility, SLA enforcement, and escalation workflows within the Security Operations (SecOps) lifecycle.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Assign incidents to analysts or teams
Why this is correct
Assigning incidents to analysts or teams is a core incident management capability in Microsoft Sentinel. Through the Incident blade, an analyst can set the Owner and assign the incident to a specific person or group, establishing accountability and routing for follow-up actions. Assignment does not change incident state by itself but ensures each case has a clear point of contact.
- ✓
Classify incidents as true positive, false positive, or benign positive
Why this is correct
Classifying incidents as true positive, false positive, or benign positive is a distinct incident management action used to record the disposition of an investigation. In Microsoft Sentinel, the analyst selects a classification and an optional reason, which feeds metrics and helps tune analytics rules to reduce noise. This classification is a judgment applied to a closed or resolved incident, not an automated or reporting function.
- ✓
Merge related incidents into a single incident
Why this is correct
Merging related incidents is an incident management capability that consolidates two or more incidents into a single entity when they represent the same underlying threat or investigation. In Sentinel, the Merge action appears for multiple incidents with similar disposition criteria, and the merged result retains all associated alerts and owner information. Merging reduces duplication and allows analysts to handle a coordinated attack as one case rather than several disjoint entries.
- ✗
Create playbooks to automate incident response
Why it's wrong here
Creating playbooks is a form of automation rather than incident management, because playbooks are Azure Logic Apps workflows that execute automated response actions when triggered. While playbooks can automate tasks that support incident handling (such as changing status or adding comments), the act of creating them belongs to the Automation and Logic Apps design experience, not to the day-to-day management of an individual incident. Incident management capabilities are those directly applied to existing incidents, like assignment and classification, whereas playbook creation is a build-time activity.
- ✗
Create workbooks to visualize incident trends
Why it's wrong here
Creating workbooks is a reporting and visualization activity rather than an incident management action. Workbooks in Microsoft Sentinel are interactive dashboards that aggregate KQL queries to display trends, detection health, and incident metrics over time. Adding or editing a workbook is done in the Workbooks blade to support monitoring and communication, but it does not directly assign, classify, merge, or otherwise operate on a specific incident.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.