Courseiva

SC-200 Respond to security incidents Practice Question

Your organization uses Microsoft Sentinel. A security analyst receives an alert for a suspicious sign-in from an unfamiliar IP address. The analyst wants to quickly check if the same IP address has been associated with any other alerts in the past 30 days. Which action should the analyst take?

⚠ Common exam trap

A common mix-up: candidates confuse proactive threat hunting actions (like creating rules or submitting to threat intelligence) with the simple investigative task of querying existing log data, leading them to select options that modify the environment rather than just query it.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Run a KQL query in the Logs blade to search the Alert table for the IP.

The Alert table in Microsoft Sentinel logs contains historical alert data, including IP addresses associated with each alert. Running a KQL query against this table allows the analyst to quickly search for the same IP address across all alerts generated in the past 30 days, enabling efficient incident correlation without modifying detection or response configurations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create an automation rule to block the IP address.

    Why it's wrong here

    Automation rules in Microsoft Sentinel are designed to orchestrate incident responses, such as assigning owners, changing statuses, or triggering playbooks, not to perform retroactive investigations. Creating an automation rule to block the IP address is a remediation step that would only affect future events and does not query the Alert table for historical occurrences. Moreover, automation rules require an incident or alert trigger, and using one to block an IP does not reveal whether that IP was present in past alerts. To identify prior involvement, you must run a KQL query against the Alert table rather than configuring an automated response.

  • ✗

    Submit the IP address to Microsoft for threat intelligence.

    Why it's wrong here

    Submitting the IP address to Microsoft for threat intelligence enrichment would provide external reputation data, such as whether the IP is known for malicious activity, but it does not search Sentinel's local Alert table for alerts already generated in your workspace. This action leverages external sources like Microsoft Defender Threat Intelligence to add context, yet it fails to answer the immediate question: has this IP triggered any alerts within your environment? Additionally, such submissions are meant for enhancing indicators, not for historical analysis of existing alert records. The only way to see past alerts involving the IP is to query the Alert table directly through the Logs blade.

  • ✗

    Create a new analytics rule to detect the IP address.

    Why it's wrong here

    Creating a new analytics rule to detect the IP address is a forward-looking approach: it schedules a KQL query to run on a recurring basis and generate alerts for future matches after the rule is enabled. This does nothing to examine the Alert table for historical events, so you would not learn whether the IP already appeared in previous alerts. Analytics rules are for detection, not investigation, and adding a rule for a single IOC would be inefficient and would not reconstruct past occurrences. To search existing alerts, you must use the Logs blade and query the Alert table manually.

  • ✓

    Run a KQL query in the Logs blade to search the Alert table for the IP.

    Why this is correct

    In Microsoft Sentinel, running a KQL query in the Logs blade against the Alert table is the correct way to search for all alerts involving a specific IP address. For example, you can execute a query like `Alert | where TimeGenerated > ago(30d) | where Entities contains "10.0.0.5"` to return every alert where that IP appears in the entity list, enabling a thorough historical investigation. The Alert table stores all alerts generated by analytics rules and data connectors, making it the authoritative source for answering whether an IP is associated with prior alerts. This read-only query provides immediate, actionable evidence without altering detection or response configurations.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.