SC-200 Respond to security incidents Practice Question
Your organization uses Microsoft Sentinel. A security incident related to a compromised user account has been fully investigated and remediated. Which THREE steps should you take to close the incident properly? (Choose three.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Verify that all related alerts are resolved or closed.
Options A, C, and D are correct. Verifying that all related alerts are resolved or closed (A) ensures no lingering issues. Changing the incident status to Closed with an appropriate classification (C) provides proper closure. Adding comments summarizing the investigation and remediation steps (D) documents the process. Option B (creating a new analytics rule) is not required for closing an incident. Option E (deleting the incident) is not recommended; incidents should be closed, not deleted.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Verify that all related alerts are resolved or closed.
Why this is correct
Closing an incident while child alerts remain active leaves orphaned detections that can regenerate the incident or skew metrics. Confirming every linked alert is resolved or closed ensures the remediation is genuinely complete before the incident itself is finalised.
- ✗
Create a new analytics rule to detect similar activity.
Why it's wrong here
Closing an incident requires assigning it, setting status to Closed with a classification, and adding a comment; new analytics rules are detection engineering, not closure. Creating a rule is correct when broadening coverage after a gap, but it neither resolves nor documents this remediated incident.
- ✓
Change the incident status to Closed and select an appropriate classification.
Why this is correct
Setting status to Closed with a classification records the outcome and root-cause category, which drives reporting, tuning and metrics. Classification is mandatory in Microsoft Sentinel when closing, distinguishing true positives from benign or undetermined findings.
- ✓
Add comments summarizing the investigation and remediation steps.
Why this is correct
Comments create the audit trail linking evidence, analysis and remediation actions to the incident record. They preserve investigative context for auditors, compliance reviews and future analysts, satisfying documentation requirements that a bare status change cannot.
- ✗
Delete the incident to clean up the workspace.
Why it's wrong here
Sentinel retains incidents for audit and hunting; deletion removes the record and its evidence rather than closing it. Deleting suits clearing test or duplicate data in a non-production workspace. Proper closure requires setting status to Closed with a classification and comment, preserving the investigation trail.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.