Courseiva

SC-200 Respond to security incidents Practice Question

Your organization uses Microsoft Sentinel. You receive an incident for a potential data exfiltration involving a sensitive blob storage container. You need to determine if the data was accessed from an unusual IP address. What should you do?

⚠ Common exam trap

SC-200 often tests the distinction between investigation actions (reviewing entity timelines, running KQL) and response/automation actions (playbooks) or configuration actions (editing analytics rules) — the trap is picking a response or config action when the question asks how to investigate.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use the Incident details pane to review the entity timeline.

The Incident details pane in Microsoft Sentinel includes an entity timeline that shows activities and events associated with entities (such as IP addresses, accounts, hosts) tied to the incident. Reviewing the entity timeline lets you see whether the blob storage was accessed from an unusual IP and correlate that IP with other activity. This is the direct investigative step for the question.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Modify the analytics rule that triggered the incident.

    Why it's wrong here

    Modifying the analytics rule during an active investigation is inappropriate because it changes the detection logic that originally produced the alert, potentially invalidating the incident's evidence and making it harder to correlate related alerts. Rule changes should follow a formal change-management process and are meant to improve future detections, not to investigate a specific event. Instead, use investigation features like the entity timeline to understand the scope without altering rule behavior.

  • ✗

    Run a playbook to collect IP information.

    Why it's wrong here

    Playbooks are Azure Logic Apps workflows designed to run automated response actions, such as blocking an IP or isolating a device, typically triggered by an alert or incident. Launching one solely to collect IP information would be an ad-hoc use that bypasses its intended response role and could introduce side effects like unintended permissions or actions. For contextual enrichment during investigation, the entity timeline in the incident details pane provides the historical IP activity without executing a workflow.

  • ✗

    Open the Sentinel workbook for storage monitoring.

    Why it's wrong here

    Workbooks are customizable dashboards that aggregate log data for monitoring trends, but a storage-monitoring workbook is not tailored to display a specific IP's historical activity in the context of this incident. Opening such a workbook would require pre-built queries and visualizations that may not exist or may not map to the incident's entities, wasting investigation time. The entity timeline is purpose-built for per-entity investigative pivots, unlike generic dashboards.

  • ✓

    Use the Incident details pane to review the entity timeline.

    Why this is correct

    The Incident details pane includes an Entities tab where the entity timeline displays a chronological sequence of activities associated with entities such as IP addresses, hosts, and accounts. This view aggregates data from multiple sources—including alerts, events, and logs—allowing the analyst to see what an IP did before, during, and after the incident. It requires no additional configuration and directly supports the investigation by revealing behavioral patterns and attack paths.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.