Courseiva

SC-200 Respond to security incidents Practice Question

Which THREE are valid incident classification categories in Microsoft Sentinel? (Select THREE.)

⚠ Common exam trap

The trap is that candidates might assume only two categories are valid, but in fact, three are recognized: False Positive, True Positive, and Benign Positive. Many confuse Benign Positive with False Positive or Informational, but all three are distinct and valid.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

False Positive

In Microsoft Sentinel, incident classification captures the analyst's triage verdict on an incident, and the three supported values are True Positive, Benign Positive, and False Positive. Option D (True Positive) is correct because it marks an incident confirmed as a genuine security threat requiring action. Option E (Benign Positive) is correct because it marks an incident that triggered legitimately but represents expected or authorized activity rather than an attack. Option A (False Positive) is correct because it marks an incident caused by inaccurate or misconfigured detection logic that does not reflect real activity. Option B (Malicious) is not a classification value — maliciousness is conveyed through severity and tactics/entities, not the classification field. Option C (Informational) is not a classification value either; it is not one of the three triage verdicts Sentinel exposes for incident classification.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    False Positive

    Why this is correct

    Microsoft Sentinel permits analysts to classify incidents as False Positive, meaning the alert was triggered but represents no genuine malicious activity. It is one of the platform's built-in classification values used to close incidents and tune analytics rules.

  • ✗

    Malicious

    Why it's wrong here

    Microsoft Sentinel incident classifications are limited to True positive, False positive, and Benign positive; Malicious is not one of them. It is tempting because analysts naturally label confirmed attacks as malicious, but that judgement is recorded through the True positive classification instead.

  • ✗

    Informational

    Why it's wrong here

    Microsoft Sentinel incident classification values are True positive, False positive, and Benign positive; Informational is a severity level, not a classification category. It is tempting because severity and classification appear together on the incident blade, making the two easy to confuse.

  • ✓

    True Positive

    Why this is correct

    True Positive is a valid classification category in Microsoft Sentinel, applied when an incident is confirmed as genuine malicious activity requiring response. It sits alongside Benign Positive and False Positive as the analyst-assigned triage classifications.

  • ✓

    Benign Positive

    Why this is correct

    Benign Positive is a valid Microsoft Sentinel incident classification, denoting activity that is genuinely suspicious-looking but authorised or expected. It sits alongside True Positive and False Positive as a built-in closure category for triaged incidents.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.