Courseiva

SC-200 Respond to security incidents Practice Question

Exhibit

Refer to the exhibit.

```json
{
  "type": "Microsoft.SecurityInsights/incidents",
  "properties": {
    "title": "Possible privilege escalation detected",
    "severity": "Medium",
    "status": "Active",
    "owner": {
      "objectId": "user@contoso.com",
      "email": "user@contoso.com",
      "assignedTo": "user@contoso.com",
      "userPrincipalName": "user@contoso.com"
    },
    "incidentNumber": 12345
  }
}
```

You are reviewing an incident in Microsoft Sentinel. The incident is assigned to a user. What does the 'assignedTo' field indicate?

⚠ Common exam trap

Test-takers frequently confuse 'assignedTo' with 'createdBy' or 'closedBy', assuming ownership implies creation or closure, but Sentinel separates these fields to track distinct stages of the incident lifecycle.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The incident is assigned to that user for investigation.

In Microsoft Sentinel, the 'assignedTo' field is used to track ownership of an incident during its lifecycle. When an incident is assigned to a user, it indicates that user is responsible for investigating and resolving the incident, not that they created or closed it. This field is set manually or via automation rules to ensure clear accountability for incident response.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The incident was created by that user.

    Why it's wrong here

    In Microsoft Sentinel, the 'Created by' property records the entity that generated the incident—typically an analytics rule, Microsoft Defender product, or a user if the incident was manually created in the portal. This is entirely separate from the 'Owner' (assignedTo) property, which is a mutable assignment used to track investigation responsibility. A user can be assigned as owner without having triggered or created the incident, so the presence of a user in the owner field does not imply that user created the incident. Moreover, creation is a one-time event while ownership can be reassigned multiple times during an incident's lifecycle.

  • ✗

    The incident was closed by that user.

    Why it's wrong here

    The incident's 'Status' field—currently 'Active'—is independent of its 'Owner' field. An incident is only closed when its status is set to 'Closed' or 'Resolved' (depending on version), which is recorded via a status change, not by the presence of a user in the owner field. Even if the owning user decides to close the incident, they must explicitly change the status to 'Closed'; the assignment itself does not affect the lifecycle state. Since the status remains 'Active', the incident has not been closed by any user, including the one shown as owner.

  • ✓

    The incident is assigned to that user for investigation.

    Why this is correct

    In Microsoft Sentinel, the 'Owner' field (also displayed as 'Assigned to' in the incident details) identifies the single user who is currently responsible for investigating and managing the incident. When a user's name appears in this field, it means that user has been assigned the incident, either manually through the 'Assign owner' button or automatically via an automation rule. This assignment is used for tracking ownership, routing work, and reporting on investigation progress, and it is the direct answer to the question of who is handling the incident. Therefore, a user in that field indicates the incident is assigned to that user for investigation.

  • ✗

    The incident is assigned to a Microsoft Entra group.

    Why it's wrong here

    The owner field in Microsoft Sentinel incidents is designed to hold a single user principal, not a Microsoft Entra group. While you might be able to select a group in some community custom connectors, the standard schema for the 'assignedTo' property stores a user object ID and displays the user's name in the UI. If the scenario shows a specific user as the owner, that is definitive evidence that the assignment is to that user as an individual, not to a group. Additionally, groups do not have their own interactive session for investigating incidents, so assigning a group would not align with the platform's per-user accountability model.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.