Question 1,405 of 1,038
SC-200 Respond to security incidents Practice Question
Your organization uses Microsoft Sentinel. A security analyst receives an alert indicating that a user account was used to sign in from an unfamiliar location. You need to investigate the incident using Microsoft Defender XDR. Which action should you take first?
⚠ Common exam trap
The trap here is that candidates often jump to immediate containment actions like password reset or account disablement, forgetting that the first step in any incident response process is to verify and classify the alert to avoid unnecessary operational impact.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Review the alert in the Microsoft Defender XDR portal and classify it as a true or false positive.
The first step in incident response is to validate the alert by reviewing it in the Microsoft Defender XDR portal. This allows the analyst to assess the alert's context, such as sign-in logs, user risk, and related entities, before taking any corrective action. Classifying the alert as a true or false positive ensures that subsequent steps (like password reset or account disablement) are based on accurate threat assessment, preventing unnecessary disruption.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create an automated playbook to reset the user's password.
Why it's wrong here
Playbooks are created after confirming the incident.
- ✓
Review the alert in the Microsoft Defender XDR portal and classify it as a true or false positive.
Why this is correct
First step is to classify the incident.
- ✗
Turn off the user account in Microsoft Entra ID.
Why it's wrong here
Containment should follow classification.
- ✗
Reset the user's password immediately to prevent further access.
Why it's wrong here
Containment should follow classification.
About these practice questions
Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →
Last reviewed: Jul 4, 2026
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.
Question Discussion
Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.
Sign in to join the discussion.