SC-200 Practice Question 3755
Exam: SC-200
Domain: Respond to security incidents
Difficulty: easy
You are investigating an incident in Microsoft Sentinel. You decide that the activity was a legitimate administrative deployment and not an attack. How should you classify the incident upon closing?
Answer Options
A
Closed: True Positive - Benign activity
B
Closed: Malicious Attack - Ongoing
C
Deleted: Corrupted Database
D
Active: In Progress
Correct Answer
A: Closed: True Positive - Benign activity
Explanation
Close the incident with the classification "Closed: True Positive - Benign activity" or "False Positive - Incorrect alert logic".