SC-200 Respond to security incidents Practice Question
You are a Security Operations Analyst using Microsoft Sentinel. An incident has been created from an analytics rule. You need to assign the incident to a specific analyst and change its status to 'Active' so that it appears in their queue. Which action should you perform in the Microsoft Sentinel incident page?
⚠ Common exam trap
The trap here is thinking that tags or automation rules are needed for manual assignment; the incident page itself has direct fields for owner and status.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use the 'Assign to' field and set the status to 'Active'
In Microsoft Sentinel, incident assignment and status are managed directly on the incident page. The 'Assign to' field sets the owner, and the status field (New, Active, Closed) controls the workflow state. Setting both assigns the incident to the analyst and marks it Active, ensuring it appears in their queue. Other actions like tagging or modifying rules do not achieve the required assignment and activation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a new automation rule to set the owner and status
Why it's wrong here
Automation rules can change owner and status, but they are triggered by incident creation or updates and are intended for automated orchestration. For a one-time manual assignment and status change, using an automation rule is unnecessary and may not take effect immediately if conditions do not match. The requirement is a manual action on a specific incident, so the incident page controls are the correct approach.
- ✗
Edit the incident's tags to include the analyst's name
Why it's wrong here
Tags are metadata used for filtering, grouping, and searching incidents, but they do not assign ownership or change the incident status. Adding a tag with a name does not route the incident to an analyst's queue or alter its workflow state. Assignment and status are separate fields that must be set explicitly; tags alone will not achieve the required routing or visibility.
- ✓
Use the 'Assign to' field and set the status to 'Active'
Why this is correct
The incident page in Microsoft Sentinel provides fields for owner (Assign to) and status (New, Active, Closed). Setting the owner to the specific analyst and changing the status to Active assigns the incident and moves it into the active workflow, making it appear in their queue. This directly fulfills the requirement to assign and activate the incident for the analyst.
- ✗
Modify the analytics rule that generated the incident
Why it's wrong here
Analytics rules define how incidents are created, including entity mapping and grouping, but they do not manage individual incident assignment or status after creation. Modifying the rule would affect future incidents, not the current one, and would not assign it to the analyst or set it to Active. The current incident must be updated directly in the incident page.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.