SC-200 Respond to security incidents Practice Question
Which TWO are valid incident management actions in Microsoft Sentinel? (Choose two.)
⚠ Common exam trap
A common mix-up: candidates confuse incident management actions in Microsoft Sentinel with those in other SIEMs (like Splunk or QRadar) where merging or deleting incidents is common, leading them to select options A or D incorrectly.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Change the incident status to 'Closed'
Changing an incident's status to 'Closed' is a standard incident management action in Microsoft Sentinel. This action finalizes the incident after investigation and remediation, and it is a core part of the incident lifecycle within the Sentinel workspace.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Merge two incidents into one
Why it's wrong here
Merging incidents is not a supported action in Microsoft Sentinel. Incidents are created from one or more alerts via analytics rules, but the console does not provide a way to combine two separate incidents into a single one. To reduce duplicate or related alerts, you can configure analytics rule grouping or use automation rules to set incident titles and severities, but the incident entities remain distinct throughout their lifecycle.
- ✗
Export the incident to a CSV file
Why it's wrong here
There is no built-in command in Microsoft Sentinel to export an individual incident to a CSV file from the incident pane. To obtain incident data outside the portal, you must use the Microsoft Sentinel REST API or query the SecurityIncident table in Log Analytics, then export the query results manually. Alternatively, you can build a workbook with a CSV export button, but the native incident-management UI does not offer this capability.
- ✓
Change the incident status to 'Closed'
Why this is correct
Changing an incident's status to 'Closed' is a valid and common incident-management action in Microsoft Sentinel. The status lifecycle includes New, In Progress, and Closed, and closing an incident indicates that it has been resolved and requires no further action. When closing, you must choose a classification (such as True Positive or False Positive) and optionally a reason, which helps preserve metadata for reporting and auditing purposes.
- ✗
Delete an incident
Why it's wrong here
Incidents in Microsoft Sentinel cannot be permanently deleted from the portal. The SecurityIncident table is an immutable audit log, so every incident remains available for historical analysis and compliance even after it is closed. The only way to remove an incident from the active queue is to change its status to Closed, which retains the full record of alerts, entities, and investigation steps.
- ✓
Assign the incident to another analyst
Why this is correct
Assigning an incident to another analyst is supported through the 'Owner' field in Microsoft Sentinel. You can set the owner to a specific user or group from Microsoft Entra ID, which transfers responsibility and makes the assignee visible to the team. Assignment can be performed manually from the incident details pane or automated via automation rules, helping to ensure incidents are routed according to organizational workflows and SLA requirements.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.