Courseiva

SC-200 Manage a security operations environment Practice Question

You are investigating a security incident in Microsoft Sentinel. You need to preserve a snapshot of the investigation including comments, bookmarks, and entities for future reference. What should you do?

⚠ Common exam trap

Many exam-takers confuse bookmarks with watchlists or automation rules, thinking that static data storage or automated actions can preserve an investigation snapshot, but only bookmarks capture the full interactive context including comments and entities.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a bookmark with the relevant data

Bookmarks in Microsoft Sentinel allow you to preserve a snapshot of an investigation, including comments, bookmarks, and entities, for future reference. Bookmarks capture the state of an investigation at a specific point in time, enabling you to revisit and share the context later.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create an automation rule to tag the incident

    Why it's wrong here

    An automation rule in Microsoft Sentinel applies actions such as tagging, assignment, or severity changes when an incident is created or updated. Tags are mutable metadata fields that do not capture the underlying query results, entities, or evidence from the investigation. While a tag might label an incident for workflow purposes, it does not provide a point-in-time snapshot and cannot be used to reconstruct the investigative data later.

  • ✓

    Create a bookmark with the relevant data

    Why this is correct

    Creating a bookmark in Microsoft Sentinel captures a snapshot of a hunting query result, including the selected rows, entities, and any comments you add, and links it to the incident. Bookmarks persist the evidence as a standalone artifact that can be re-opened, shared, and investigated, making them the correct choice for preserving the incident data at a specific time. Unlike other options, a bookmark maintains the contextual provenance of how you found the evidence.

  • ✗

    Add the entities to a watchlist

    Why it's wrong here

    A watchlist is a scalable list of values or entities that Sentinel stores as tabular data for correlation, enrichment, or detection rules, not as an evidentiary snapshot. Adding entities to a watchlist only creates or updates a list entry, losing the surrounding incident context, query results, and investigator notes. Watchlists are intended for operational data like IP address deny lists or host inventories, not for freezing the state of an investigation.

  • ✗

    Close the incident as a false positive

    Why it's wrong here

    Closing an incident as a false positive sets a classification and resolution reason, which changes the incident lifecycle but does not generate a forensic capture of the investigation. While the incident comments and history remain in the workspace for the retention period, the important query results and entity relationships are not bundled into a reusable evidence package. Furthermore, closing an incident as a false positive may suppress recurrence alerts or mislead future analysts about the validity of the data, so it is not an archive mechanism.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.