Courseiva

SC-200 Respond to security incidents Practice Question

You receive an incident in Microsoft Sentinel that is a low-confidence alert from Microsoft Defender for Identity. What should be your first step?

⚠ Common exam trap

Test-takers frequently assume low-confidence alerts are always false positives and close them immediately, but the correct triage process requires investigation first to avoid missing subtle attacks that manifest as low-confidence alerts.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Investigate the alert by reviewing related entities and logs.

A low-confidence alert from Microsoft Defender for Identity indicates a potential but uncertain threat. The first step should always be to investigate the alert by reviewing related entities and logs to gather context and determine if the alert is a true positive or false positive. Prematurely closing, escalating, or isolating without investigation risks missing a real threat or causing unnecessary disruption.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Investigate the alert by reviewing related entities and logs.

    Why this is correct

    Investigating the alert by reviewing related entities (e.g., user, IP, host) and the underlying logs is the correct first step because it determines whether the detected activity is a true positive. Sentinel's incident investigation canvas allows you to track entity relationships, pivot to related events, and query KQL to confirm the alert's validity before any containment or remediation action is taken.

  • ✗

    Close the incident as a false positive.

    Why it's wrong here

    Closing the incident as a false positive without examining the alert's underlying log entries, entity context, or matching the activity against MITRE ATT&CK techniques risks suppressing a genuine threat. A low-severity incident is not inherently a false positive; many attack chains start with low-impact signs, and unverified closure can also degrade future detection tuning by feeding false assumptions into analytics rules.

  • ✗

    Escalate to senior management.

    Why it's wrong here

    Escalating to senior management is inappropriate at this stage because escalation should be reserved for incidents that have been confirmed as high-impact, business-critical, or requiring executive decisions on resource allocation. A low-severity alert has not yet been investigated, so there is no validated threat scope or organizational impact to justify disrupting management's time and attention.

  • ✗

    Isolate the affected account immediately.

    Why it's wrong here

    Isolating the affected account immediately could lock out a legitimate user and disrupt business operations before there is evidence that the account is truly compromised. Account isolation is a containment step that should follow investigation and validation—ideally informed by UEBA-driven risk scores, sign-in logs, and entity behavior analytics—rather than being applied reactively to every low-severity alert.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.