nerdexam
Microsoft

SC-200 · Question #86

You are investigating an incident in Azure Sentinel that contains more than 127 alerts. You discover eight alerts in the incident that require further investigation. You need to escalate the alerts…

The correct answer is D. Assign the incident. Incidents can be assigned to a specific user or to a group. For each incident you can assign an owner, by setting the Owner field. All incidents start as unassigned. You can also add comments so that other analysts will be able to understand what you investigated and what your…

Submitted by the_admin· Apr 18, 2026Manage incident response

Question

You are investigating an incident in Azure Sentinel that contains more than 127 alerts. You discover eight alerts in the incident that require further investigation. You need to escalate the alerts to another Azure Sentinel administrator. What should you do to provide the alerts to the administrator?

Options

  • ACreate a Microsoft incident creation rule
  • BShare the incident URL
  • CCreate a scheduled query rule
  • DAssign the incident

How the community answered

(35 responses)
  • A
    3% (1)
  • B
    3% (1)
  • C
    9% (3)
  • D
    86% (30)

Explanation

Incidents can be assigned to a specific user or to a group. For each incident you can assign an owner, by setting the Owner field. All incidents start as unassigned. You can also add comments so that other analysts will be able to understand what you investigated and what your concerns are around the incident. https://docs.microsoft.com/en-us/azure/sentinel/investigate-cases

Topics

#Microsoft Sentinel#Incident Management#Incident Escalation#Security Operations

Community Discussion

No community discussion yet for this question.

Full SC-200 Practice