Courseiva

SC-200 Respond to security incidents Practice Question

Which THREE steps should be included in a Microsoft Sentinel playbook for automatic incident response when a high-severity alert fires?

⚠ Common exam trap

Watch out — candidates often confuse 'pausing' an incident with 'suppression' or 'tuning' rules, but in the context of automated response, any delay for high-severity alerts is unacceptable because it contradicts the goal of immediate containment.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Investigate the alert by enriching with threat intelligence

Microsoft Sentinel playbooks, built on Azure Logic Apps, can automatically enrich alerts with threat intelligence from sources like the Threat Intelligence API or integrated TI platforms (e.g., VirusTotal, AlienVault OTX). This enrichment provides context (e.g., known malicious IPs, hashes, or domains) directly within the incident, enabling faster triage and informed response decisions without manual investigation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Investigate the alert by enriching with threat intelligence

    Why this is correct

    In Microsoft Sentinel, enriching an alert with threat intelligence is a standard investigative step: you pivot on entities such as IPs, domains, or hashes to query TI feeds and identify known malicious context, which helps validate the alert's severity and false-positive risk. This enrichment often leverages the built-in Threat Intelligence workbook or the hunting queries, enabling the analyst to correlate the current alert with historical compromise activity. It directly supports the 'Investigate' phase of the incident response lifecycle, making it a correct step.

  • ✓

    Notify the security team via email or Teams

    Why this is correct

    Notifying the security team via email or Teams is an appropriate and required action in Microsoft Sentinel incident response, because it triggers human review and ensures other analysts or responders are aware of the high-severity event. In Sentinel, this can be automated through a playbook that uses connectors like Microsoft Teams or Outlook to send an alert message to a security operations channel or distribution list. This step aligns with the 'Respond' phase and helps ensure the incident is staffed without delay, so it is a correct choice.

  • ✗

    Pause the incident for 24 hours before taking action

    Why it's wrong here

    Pausing an incident for 24 hours is incorrect because it violates the principle of timely response to high-severity alerts; Sentinel incidents are expected to be triaged and acted upon quickly to prevent lateral movement and reduce dwell time. A deliberate delay of 24 hours could allow an attacker to escalate privileges, exfiltrate data, or destroy evidence, and it conflicts with typical SOC SLAs and NIST incident response guidance. There is no standard Sentinel runbook that instructs analysts to 'sleep' on an active incident, so this option is wrong.

  • ✗

    Create a new Azure resource for logging

    Why it's wrong here

    Creating a new Azure resource for logging is not a valid incident response step in Microsoft Sentinel, because the platform already captures relevant logs from existing data sources—such as Azure Activity, Microsoft 365 Defender, and third-party connectors—and you would not add a new resource mid-incident to gather evidence. Doing so would take time, potentially require network changes, and could even generate misleading telemetry that isn't correlated with the incident. Standard response steps focus on investigation, notification, and containment, not provisioning infrastructure, so this is incorrect.

  • ✓

    Contain the threat by blocking indicators

    Why this is correct

    Containing the threat by blocking indicators is a key response action in Microsoft Sentinel, typically executed via a playbook that sends block commands to security products like Microsoft Defender for Endpoint, Windows Defender Firewall, or third-party tools such as Palo Alto and Fortinet. Blocking malicious IPs, domains, or file hashes immediately stops communication with the attacker's C2 infrastructure and limits the blast radius, directly addressing the 'Respond' and 'Contain' phases. Because the question asks for valid steps, this is a correct choice.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.