AZ-500 Manage identity and access Practice Question
A security analyst is using Microsoft Sentinel to investigate a security incident. The analyst needs to view all related events, alerts, and entities (users, IPs, hosts) in a single, interactive graph to understand the full scope of the attack. Which Microsoft Sentinel feature should they use?
⚠ Common exam trap
It's easy for candidates to confuse the Incident timeline (which shows a linear history) with the Investigation graph (which shows relational connections), leading them to choose the timeline option when the question explicitly asks for an interactive graph to understand the full scope of an attack.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Investigation graph
The Investigation graph in Microsoft Sentinel provides an interactive, visual map that correlates all related events, alerts, and entities (such as users, IPs, and hosts) for a given incident. This allows the analyst to explore the full scope of an attack by dragging and dropping entities to uncover hidden relationships, making it the correct feature for this scenario.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Incident timeline
Why it's wrong here
The incident timeline in Microsoft Sentinel is a chronological, time-ordered list of the alerts, anomalies, and bookmarks attached to an incident. It is useful for establishing the order of events (e.g., which alert fired first), but it does not visualize the underlying entity graph—such as which user, IP address, or host communicated with another host. Because it renders a flat list rather than linked nodes, it cannot illustrate the attack path or the full scope of an incident.
- ✓
Investigation graph
Why this is correct
The investigation graph in Microsoft Sentinel is purpose-built for interactive incident analysis: it displays the incident's extracted entities—such as accounts, IP addresses, hosts, and URLs—as nodes and connects them to the alerts that reference those entities, creating an attack-path visualization. From any node, an analyst can expand to see related alerts, user activities, and other entities, helping to identify the root cause and the scope of the threat. This is the correct tool because it directly supports the analyst's need to examine entity relationships, unlike a sequential timeline or a proactive query engine.
- ✗
Hunting
Why it's wrong here
Microsoft Sentinel's hunting capability is a proactive threat-hunting tool that runs KQL queries over a defined time range to identify suspicious behavior before or independently of an incident. Although hunt results can be bookmarked and later added to an incident, hunting itself does not provide an incident-specific, entity-relationship graph and is not designed for analyzing an already-created incident. Using hunting here would trigger a broad, unguided search when the investigation should instead focus on the entities and alerts already associated with the incident.
- ✗
Analytics rules
Why it's wrong here
Analytics rules in Microsoft Sentinel are configuration objects that define detection logic—for example, scheduled queries, anomaly thresholds, or correlation pipelines—that evaluate data ingestion and create alerts when a condition is met. These rules operate at the alert-creation stage; once an incident is generated, the rule is no longer part of the incident investigation interface and offers no interactive canvas for exploring entity associations. Therefore, an analyst investigating an existing incident would not use analytics rules to visualize entity connections.
Go deeper
Related to this question
About these practice questions
This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.