Courseiva
Question 1,405 of 1,038
Respond to security incidentsmediumMultiple ChoiceObjective-mapped

SC-200 Respond to security incidents Practice Question

Your organization uses Microsoft Sentinel. A security analyst receives an alert indicating that a user account was used to sign in from an unfamiliar location. You need to investigate the incident using Microsoft Defender XDR. Which action should you take first?

⚠ Common exam trap

The trap here is that candidates often jump to immediate containment actions like password reset or account disablement, forgetting that the first step in any incident response process is to verify and classify the alert to avoid unnecessary operational impact.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Review the alert in the Microsoft Defender XDR portal and classify it as a true or false positive.

The first step in incident response is to validate the alert by reviewing it in the Microsoft Defender XDR portal. This allows the analyst to assess the alert's context, such as sign-in logs, user risk, and related entities, before taking any corrective action. Classifying the alert as a true or false positive ensures that subsequent steps (like password reset or account disablement) are based on accurate threat assessment, preventing unnecessary disruption.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Create an automated playbook to reset the user's password.

    Why it's wrong here

    Playbooks are created after confirming the incident.

  • Review the alert in the Microsoft Defender XDR portal and classify it as a true or false positive.

    Why this is correct

    First step is to classify the incident.

  • Turn off the user account in Microsoft Entra ID.

    Why it's wrong here

    Containment should follow classification.

  • Reset the user's password immediately to prevent further access.

    Why it's wrong here

    Containment should follow classification.

About these practice questions

Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Last reviewed: Jul 4, 2026

Question Discussion

Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.

Loading comments…

Sign in to join the discussion.

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.