SC-200 Respond to security incidents Practice Question
Your organization uses Microsoft Sentinel. A security analyst receives an alert from a custom analytics rule that triggers on a specific sequence of failed logon attempts followed by a successful logon from an unusual location. The incident is generated but the analyst is not sure if the activity is malicious or a user error. What should the analyst do first to quickly gather additional context?
⚠ Common exam trap
SC-200 often tests the difference between investigation and detection-engineering actions, so the trap is choosing to modify or create analytics rules (a detection task) instead of using the Investigation graph to gather context on the current incident.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use the Investigation graph to explore related entities and events
The Investigation graph in Microsoft Sentinel is designed to let analysts visually explore an incident's related entities (users, hosts, IPs) and their connections, quickly surfacing additional context such as other alerts, sign-ins, and events tied to the same entities. It is the fastest first step to determine whether the activity is malicious or benign without writing queries.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Run a KQL query across the entire workspace to find all related events
Why it's wrong here
A broad KQL query across the whole workspace returns unrelated events and delays triage, rather than pivoting on the specific entities in this incident. It is tempting because KQL is Sentinel's investigation language, but hunting should start from the incident's entities, not a workspace-wide sweep.
- ✗
Create a new analytics rule to detect similar patterns
Why it's wrong here
Creating another analytics rule generates future detections and provides no context about the current incident. It is tempting because similar patterns may recur, but rule authoring is detection coverage work, not the immediate enrichment step for an existing alert.
- ✓
Use the Investigation graph to explore related entities and events
Why this is correct
The Investigation graph maps the incident's entities—accounts, hosts, IPs—and their linked events, letting the analyst pivot across the failed-then-successful logon sequence and unusual location in one view, satisfying the need to rapidly gather context before deciding whether the activity is malicious.
- ✗
Modify the existing analytics rule to add more conditions
Why it's wrong here
Editing the analytics rule changes future detection logic and does nothing to enrich the incident already raised. It is tempting because tuning rules reduces noise, but that is a detection-engineering task, not the first step for gathering context on an existing incident.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.