nerdexam
Microsoft

SC-200 · Question #165

A SOC analyst found out about an event of interest. What is the next step to take it forward for further review?

The correct answer is A. Flag. In Microsoft 365 Defender and SOC workflows, when an analyst identifies an event of interest that warrants further review or escalation, the correct action is to 'Flag' it. Flagging marks the alert or event so other analysts or higher-tier teams know it requires additional…

Submitted by ravi_2018· Apr 18, 2026Manage incident response

Question

A SOC analyst found out about an event of interest. What is the next step to take it forward for further review?

Options

  • AFlag
  • BTag
  • CHighlight
  • DClose

How the community answered

(38 responses)
  • A
    92% (35)
  • B
    5% (2)
  • C
    3% (1)

Explanation

In Microsoft 365 Defender and SOC workflows, when an analyst identifies an event of interest that warrants further review or escalation, the correct action is to 'Flag' it. Flagging marks the alert or event so other analysts or higher-tier teams know it requires additional attention. 'Tag' is used for categorization/labeling, 'Highlight' is not a standard SOC action in this context, and 'Close' would dismiss the event rather than escalate it.

Topics

#SOC workflow#Incident response process#Event escalation#Alert triage

Community Discussion

No community discussion yet for this question.

Full SC-200 Practice