SC-200 Respond to security incidents Practice Question
Your organization uses Microsoft Sentinel. A fusion incident was created involving multiple alerts from different sources. You need to investigate the incident to determine if it is a true positive. What is the first step you should take?
⚠ Common exam trap
The trap here is that candidates often jump to running KQL queries (Option A) because they associate investigation with raw log analysis, but the correct first step is to use Sentinel's built-in incident visualization to understand the correlation before querying.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Review the incident timeline and entity mapping in the incident details.
The first step in investigating a Fusion incident in Microsoft Sentinel is to review the incident timeline and entity mapping. This provides a consolidated view of all correlated alerts, their timestamps, and the entities involved (e.g., IP addresses, user accounts), enabling you to quickly assess whether the alerts are logically connected and indicative of a true positive attack chain. Starting with this high-level overview is efficient before diving into raw logs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Run a KQL query on the raw logs to see if the alerts are connected.
Why it's wrong here
Running a KQL query against raw Log Analytics tables is a deep investigation technique that is appropriate only after you have understood the incident's existing evidence. The fusion incident already contains correlated alerts and entity relationships, so querying raw logs at the outset bypasses that context and duplicates effort without verifying whether the alerts are actually connected. Any such query would also lack the temporal and entity-centric view that the incident timeline provides, making it an ineffective first step for triage.
- ✗
Assign the incident to a senior analyst for further investigation.
Why it's wrong here
Assigning the incident to a senior analyst before reviewing the incident details bypasses the required initial triage, because you cannot yet determine the incident's scope, severity, or whether it warrants escalation. The assignment action is meant to route a confirmed or at least preliminarily characterized incident to the right owner, not to delegate an unexamined alert. Without that first review, you have no basis to decide whom to assign, and you risk delaying a response to a potential true positive.
- ✓
Review the incident timeline and entity mapping in the incident details.
Why this is correct
Opening the incident details and examining the timeline and entity mapping is the correct first step because it shows the sequential events of the attack and the relationships between involved entities such as users, hosts, and IP addresses. Sentinel's fusion engine generates this correlation by combining multiple low-fidelity alerts across the attack chain, and the timeline helps you see if the alerts are sequentially connected. The entity mapping directly reveals shared indicators that might otherwise look disconnected when reading alert titles alone.
- ✗
Close the incident as a false positive if the alerts seem unrelated.
Why it's wrong here
Closing the incident as a false positive simply because the alerts 'seem unrelated' is dangerous because fusion incidents often combine alerts from different stages of an attack where the entities and alert names do not immediately appear connected. A false-positive determination requires verifying each alert's legitimacy, checking the timeline for progression, and confirming no entity relationships exist—not relying on a visual impression. Premature closure can hide a multi-stage attack that is intentionally exploiting that apparent disjointedness to evade detection.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.