Courseiva

SC-200 Respond to security incidents Practice Question

Which THREE steps are part of the incident response process when using Microsoft Sentinel?

⚠ Common exam trap

It's easy for candidates to confuse the proactive detection step of creating analytics rules (which generates incidents) with the reactive incident response step of triaging and investigating those incidents, leading them to incorrectly select Option A as part of the response process.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Investigate the incident using hunting queries and entity timelines.

Investigating an incident using hunting queries and entity timelines is a core step in the Microsoft Sentinel incident response process. After an incident is created, analysts use KQL-based hunting queries to proactively search for related threats and leverage entity timelines to visualize the sequence of events and entity interactions, which is essential for understanding the scope and impact of the incident.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Identify the incident by creating an analytics rule.

    Why it's wrong here

    Creating an analytics rule is a detection configuration activity, not an incident response step, because it occurs before any incident exists. In Microsoft Sentinel, analytics rules define detection logic and automatically generate incidents when threats are identified, so the rule itself cannot be used to triage or investigate an incident. Incident identification is a proactive threat-hunting process that happens prior to rule creation, and once the rule fires, the response process begins with the generated incident.

  • ✓

    Investigate the incident using hunting queries and entity timelines.

    Why this is correct

    Investigation is the phase where the analyst uses threat hunting queries, entity timelines, and the investigation graph to reconstruct the attack chain and determine the full scope of compromise. This step involves correlating alerts, user sign-in data, and network artifacts to identify the root cause, affected assets, and potential data loss. In Microsoft Sentinel, a KQL query might pivot on a compromised entity to reveal lateral movement, while the entity timeline provides a chronological view of activities that contextualizes each alert.

  • ✓

    Remediate the incident by running playbooks or manual actions.

    Why this is correct

    Remediation is the containment and eradication phase in which the analyst executes playbook or manual actions to neutralize the threat and restore normal operations. Microsoft Sentinel playbooks, built on Power Automate and Azure Logic Apps, automate response tasks such as disabling compromised accounts, blocking malicious IP addresses, or quarantining files, and can be triggered automatically by automation rules. Manual actions are used when automated responses are insufficient, ensuring tailored containment for complex incidents.

  • ✗

    Report the incident to the security team via email.

    Why it's wrong here

    Reporting via email is an administrative communication method, not a core phase of Sentinel's incident response process, which follows the triage, investigation, remediation, and post-incident sequence. In a proper workflow, incident reporting is handled through integrated ticketing systems like ServiceNow or through internal incident management tools, ensuring auditability and context. Relying on email for reporting would introduce delay and lack the structured data needed for tracking, and it is not one of the defined steps in Microsoft's incident response playbook.

  • ✓

    Triage the incident to determine severity.

    Why this is correct

    Triage is the first and most critical step in the incident response process, where the analyst assesses the incident's severity, impact, and urgency to assign a priority. This prioritization determines the order of investigation and remediation, ensuring that high-impact incidents like ransomware or data exfiltration receive immediate attention. In Microsoft Sentinel, triage uses severity levels and tags from analytics rules, but the analyst's judgment is essential to adjust priority based on contextual factors.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.