SC-200 Practice Question 3755

Exam: SC-200
Domain: Respond to security incidents
Difficulty: easy
You are investigating an incident in Microsoft Sentinel. You decide that the activity was a legitimate administrative deployment and not an attack. How should you classify the incident upon closing?

Answer Options

A
Closed: True Positive - Benign activity
B
Closed: Malicious Attack - Ongoing
C
Deleted: Corrupted Database
D
Active: In Progress

Correct Answer

A: Closed: True Positive - Benign activity

Explanation

Close the incident with the classification "Closed: True Positive - Benign activity" or "False Positive - Incorrect alert logic".