SC-200 Respond to security incidents Practice Question
Your organization uses Microsoft Sentinel with Fusion and Microsoft Security incident creation rules. You receive a high-severity incident from Microsoft Defender for Cloud Apps. The incident has a low confidence score. What should you do first?
⚠ Common exam trap
Many candidates assume low confidence automatically means false positive, leading them to dismiss or suppress the alert, but the correct approach is to validate through correlation before making a decision.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Validate the alert by correlating with other logs.
A low confidence score indicates the alert may be a false positive, but it should not be dismissed without investigation. In Microsoft Sentinel, low confidence alerts from Defender for Cloud Apps require validation through correlation with other logs (e.g., Microsoft Entra ID sign-ins, network logs) to confirm malicious activity before taking action. This aligns with the incident response process of triage and verification, not immediate dismissal or suppression.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Dismiss the incident as a false positive due to low confidence.
Why it's wrong here
Low confidence in a Fusion or Defender for Cloud Apps alert indicates weak or insufficient evidence, not that the activity is benign. Attackers often deliberately use low-confidence signals to evade detection, so dismissing the incident without investigation could allow a real threat to persist. Investigation is mandatory to determine the actual risk before any disposition decision.
- ✗
Suppress all future alerts from Defender for Cloud Apps with low confidence.
Why it's wrong here
Suppressing all future low-confidence alerts from Defender for Cloud Apps is a broad, irreversible action based solely on a confidence score, which ignores the possibility that these alerts may be precursors to a larger attack or may represent legitimate but unusual behavior. This approach creates a blind spot because even low-confidence detections can be true positives when correlated with other indicators. Instead, tuning should be based on specific patterns, not confidence alone.
- ✗
Escalate the incident to the SOC manager immediately.
Why it's wrong here
Escalating to the SOC manager immediately without first performing any validation or triage is inefficient and contributes to alert fatigue, as the manager would receive an unanalyzed alert lacking context. The SOC manager expects incident details, evidence, and a preliminary analysis to make an informed decision, not a raw alert that may be a false positive. Escalation is reserved for confirmed high-priority incidents or those requiring additional authority or resources.
- ✓
Validate the alert by correlating with other logs.
Why this is correct
Validating the alert by correlating it with other logs is the correct first step in incident triage. This involves checking user sign-in logs, Microsoft Entra ID audit logs, Microsoft 365 audit logs, and endpoint/data loss prevention events for corroborating evidence of the same activity. Correlation helps confirm whether the Alert is a true positive, a false positive, or part of a bigger campaign, enabling proper prioritization and response.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.