Courseiva

SC-200 Respond to security incidents Practice Question

Your organization uses Microsoft Sentinel. You receive a high-severity incident indicating a potential data exfiltration from an Azure Storage account. The incident contains entities such as IP addresses and user accounts. Which step should you perform first to contain the threat?

⚠ Common exam trap

SC-200 often tests the principle of 'investigate before you contain' to ensure candidates understand the incident response lifecycle and avoid premature actions that could harm business operations or destroy evidence.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Investigate the incident to confirm the activity is malicious

In Microsoft Sentinel, the first step after receiving a high-severity incident is to investigate and confirm whether the activity is truly malicious. This triage step prevents unnecessary containment actions that could disrupt legitimate business operations. Only after confirming the threat should you proceed with containment measures like blocking IPs or disabling accounts.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Contact the user associated with the storage account

    Why it's wrong here

    Contacting the user is an investigation or notification step, not containment, and delays blocking active exfiltration. It is tempting because identifying the account owner feels prudent, yet containment requires immediately restricting the compromised identity or storage access before evidence is lost.

  • ✗

    Block the suspicious IP address in the Azure Firewall

    Why it's wrong here

    Blocking the IP address is a network-layer action, but exfiltration from an Azure Storage account typically occurs over authorised endpoints or compromised credentials, so the IP may be irrelevant. It is tempting as familiar perimeter containment, yet revoking the compromised identity's access addresses the actual vector.

  • ✓

    Investigate the incident to confirm the activity is malicious

    Why this is correct

    Confirming whether the flagged activity is genuinely malicious precedes containment, because isolating resources or disabling accounts on a false positive causes unnecessary disruption. Investigation validates the incident's entities and scope, ensuring subsequent containment actions target a real threat.

  • ✗

    Disable the storage account

    Why it's wrong here

    Disabling the storage account halts exfiltration but disrupts all workloads and users depending on it, exceeding necessary containment. It is tempting as a decisive cut-off, yet the correct first action targets the specific compromised identity or access path rather than the entire shared resource.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.