Courseiva

SC-200 Respond to security incidents Practice Question

Which TWO are valid incident management actions in Microsoft Sentinel? (Choose two.)

⚠ Common exam trap

A common mix-up: candidates confuse incident management actions in Microsoft Sentinel with those in other SIEMs (like Splunk or QRadar) where merging or deleting incidents is common, leading them to select options A or D incorrectly.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Change the incident status to 'Closed'

Changing an incident's status to 'Closed' is a standard incident management action in Microsoft Sentinel. This action finalizes the incident after investigation and remediation, and it is a core part of the incident lifecycle within the Sentinel workspace.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Merge two incidents into one

    Why it's wrong here

    Merging incidents is not a supported action in Microsoft Sentinel. Incidents are created from one or more alerts via analytics rules, but the console does not provide a way to combine two separate incidents into a single one. To reduce duplicate or related alerts, you can configure analytics rule grouping or use automation rules to set incident titles and severities, but the incident entities remain distinct throughout their lifecycle.

  • ✗

    Export the incident to a CSV file

    Why it's wrong here

    There is no built-in command in Microsoft Sentinel to export an individual incident to a CSV file from the incident pane. To obtain incident data outside the portal, you must use the Microsoft Sentinel REST API or query the SecurityIncident table in Log Analytics, then export the query results manually. Alternatively, you can build a workbook with a CSV export button, but the native incident-management UI does not offer this capability.

  • ✓

    Change the incident status to 'Closed'

    Why this is correct

    Changing an incident's status to 'Closed' is a valid and common incident-management action in Microsoft Sentinel. The status lifecycle includes New, In Progress, and Closed, and closing an incident indicates that it has been resolved and requires no further action. When closing, you must choose a classification (such as True Positive or False Positive) and optionally a reason, which helps preserve metadata for reporting and auditing purposes.

  • ✗

    Delete an incident

    Why it's wrong here

    Incidents in Microsoft Sentinel cannot be permanently deleted from the portal. The SecurityIncident table is an immutable audit log, so every incident remains available for historical analysis and compliance even after it is closed. The only way to remove an incident from the active queue is to change its status to Closed, which retains the full record of alerts, entities, and investigation steps.

  • ✓

    Assign the incident to another analyst

    Why this is correct

    Assigning an incident to another analyst is supported through the 'Owner' field in Microsoft Sentinel. You can set the owner to a specific user or group from Microsoft Entra ID, which transfers responsibility and makes the assignee visible to the team. Assignment can be performed manually from the incident details pane or automated via automation rules, helping to ensure incidents are routed according to organizational workflows and SLA requirements.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.