Courseiva

SC-200 Respond to security incidents Practice Question

Your security team uses Microsoft Sentinel analytics rules to detect brute-force attacks. A rule triggers when more than 10 failed logins occur within 5 minutes from a single IP. An incident is generated. Which first step should the analyst take?

⚠ Common exam trap

The trap here is that candidates often jump to a reactive containment action (blocking the IP) without first validating the alert, confusing incident triage with incident response escalation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Investigate the incident details

The first step in incident response within Microsoft Sentinel is to investigate the incident details to validate the alert and understand the scope. This aligns with the NIST incident response lifecycle (identification and analysis) and Sentinel's built-in investigation graph, which allows analysts to correlate entities, timelines, and related events before taking any containment action.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Block the source IP address on the firewall

    Why it's wrong here

    Blocking the source IP on the firewall is a reactive containment step that should be taken only after investigation confirms the IP is genuinely malicious. In Microsoft Sentinel, the incident may include alerts triggered by a shared NAT IP or a legitimate user repeatedly mistyping passwords, so an immediate block could cause service outages for many users. Furthermore, you need to check threat intelligence, verify the IP's reputation, and correlate it with other signals before initiating a firewall change, especially since the block should be executed through an automated playbook only under validated conditions.

  • ✓

    Investigate the incident details

    Why this is correct

    Investigating the incident details is the correct first step because it provides the necessary context to determine the scope and severity of the threat. In Microsoft Sentinel, you open the incident to review the full timeline, related alerts, entities (accounts, hosts, IPs), and raw evidence gathered by the analytics rule. This investigation enables triage—confirming whether the failed logins indicate a brute-force attack, a password spray, or a false positive—and guides all subsequent containment and remediation decisions with data rather than assumptions.

  • ✗

    Notify the users of the failed login attempts

    Why it's wrong here

    Notifying users of failed login attempts is premature because the incident may involve an attacker's operations, and alerting users could compromise the investigation or trigger a destructive response from the adversary. Additionally, in a large enterprise, users may not be the ones initiating those attempts, and mass notification could create confusion or panic without actionable guidance. Communication of this type typically occurs only after the investigation has confirmed which accounts are impacted and a clear remediation and communication plan has been established, in line with incident response protocols.

  • ✗

    Reset passwords for all affected accounts

    Why it's wrong here

    Resetting passwords for all affected accounts before investigating is dangerous because it may lock out legitimate users and disrupt the ability to monitor the attacker's behavior. Without investigation, you don't know which accounts are truly compromised, nor whether the failed attempts came from a password spray targeting many users or from a single attacker using one account. Premature password resets could also alert the attacker that they are detected, causing them to change tactics or destroy evidence before you can complete the forensic analysis and determine the full attack path.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.