Courseiva

SC-200 Respond to security incidents Practice Question

Your organization uses Microsoft Sentinel. A security incident related to a compromised user account has been fully investigated and remediated. Which THREE steps should you take to close the incident properly? (Choose three.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Verify that all related alerts are resolved or closed.

Options A, C, and D are correct. Verifying that all related alerts are resolved or closed (A) ensures no lingering issues. Changing the incident status to Closed with an appropriate classification (C) provides proper closure. Adding comments summarizing the investigation and remediation steps (D) documents the process. Option B (creating a new analytics rule) is not required for closing an incident. Option E (deleting the incident) is not recommended; incidents should be closed, not deleted.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Verify that all related alerts are resolved or closed.

    Why this is correct

    Closing an incident while child alerts remain active leaves orphaned detections that can regenerate the incident or skew metrics. Confirming every linked alert is resolved or closed ensures the remediation is genuinely complete before the incident itself is finalised.

  • ✗

    Create a new analytics rule to detect similar activity.

    Why it's wrong here

    Closing an incident requires assigning it, setting status to Closed with a classification, and adding a comment; new analytics rules are detection engineering, not closure. Creating a rule is correct when broadening coverage after a gap, but it neither resolves nor documents this remediated incident.

  • ✓

    Change the incident status to Closed and select an appropriate classification.

    Why this is correct

    Setting status to Closed with a classification records the outcome and root-cause category, which drives reporting, tuning and metrics. Classification is mandatory in Microsoft Sentinel when closing, distinguishing true positives from benign or undetermined findings.

  • ✓

    Add comments summarizing the investigation and remediation steps.

    Why this is correct

    Comments create the audit trail linking evidence, analysis and remediation actions to the incident record. They preserve investigative context for auditors, compliance reviews and future analysts, satisfying documentation requirements that a bare status change cannot.

  • ✗

    Delete the incident to clean up the workspace.

    Why it's wrong here

    Sentinel retains incidents for audit and hunting; deletion removes the record and its evidence rather than closing it. Deleting suits clearing test or duplicate data in a non-production workspace. Proper closure requires setting status to Closed with a classification and comment, preserving the investigation trail.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.