Courseiva

SC-200 Respond to security incidents Practice Question

Your organization uses Microsoft Sentinel. A security incident is created, and the assigned analyst needs to perform initial triage. What is the first step the analyst should take according to Microsoft best practices for incident response?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Review the incident details and verify the alert is a true positive.

The first step in the Microsoft incident response process is to verify the alert and determine its validity. Option A is wrong because containment should follow after verification. Option B is wrong because escalating before verification bypasses triage. Option D is wrong because detailed investigation comes after initial triage.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Contain the affected resources immediately to prevent further damage.

    Why it's wrong here

    Containing the affected resources immediately is a reactive response that should only occur after you have verified the alert as a true positive in Microsoft Sentinel. Taking containment action without validation risks disrupting legitimate business operations and triggering a false-positive-driven outage, and it can also destroy volatile evidence such as active processes and network connections that the incident record still needs for analysis. In the Sentinel incident workflow, containment is a deliberate step that follows triage and classification, not the first action.

  • ✗

    Run a full investigation using Microsoft 365 Defender hunting queries.

    Why it's wrong here

    Running a full investigation using Microsoft 365 Defender hunting queries is premature because investigation should happen only after the incident has been confirmed as a genuine security event. Microsoft 365 Defender advanced hunting is designed for proactive threat hunting across email, endpoints, identities, and cloud apps, not as the initial validation mechanism for a single Sentinel alert. At this stage you first need to examine the incident details in Sentinel, including the originating analytics rule and entity timeline, before launching broad hunting queries that could waste time and produce irrelevant results.

  • ✓

    Review the incident details and verify the alert is a true positive.

    Why this is correct

    The correct first step is to open the incident in Microsoft Sentinel and review its details to verify the alert is a true positive. This means checking the incident's severity, status, entities, MITRE ATT&CK tactics, and the raw data or logs that triggered the analytics rule, then correlating it with other alerts on the same resource to confirm the activity is genuinely malicious. Only after this validation should you decide whether to contain, investigate, or escalate, because taking response actions on an unverified false positive can cause unnecessary damage.

  • ✗

    Escalate the incident to the senior security team.

    Why it's wrong here

    Escalating directly to the senior security team is wrong at this stage because escalation should happen after initial triage has determined that the incident is a true positive and has assessed business impact or priority. Escalating an unvalidated alert could overwhelm senior analysts with false positives and undermine the credibility of the reporting process. The first step is always to review the incident details in Sentinel and confirm the alert before involving higher-tier teams, which keeps the incident response workflow structured and effective.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.