Courseiva
Manage identity and access →mediumMultiple Choice

AZ-500 Manage identity and access Practice Question

A security operations team uses Microsoft Sentinel. They are investigating a security incident that involves multiple alerts from different Azure resources. They need to see the entire attack timeline and all related entities (such as user accounts, IP addresses, and hosts) in a single, visual graph to understand the scope of the attack. Which Microsoft Sentinel feature should they use?

⚠ Common exam trap

Many candidates confuse the Incident dashboard (which shows a list of incidents) with the Investigation graph (which provides the interactive visual graph of entities and timeline), leading them to select the dashboard option because it sounds like the place to 'see' incident details.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Investigation graph

The Investigation graph in Microsoft Sentinel is specifically designed to visually map the relationships between alerts, entities (such as user accounts, IP addresses, and hosts), and the attack timeline. It allows security analysts to explore the scope of an incident by interactively expanding nodes and viewing connections, which directly meets the requirement for a single visual graph showing the entire attack timeline and related entities.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Investigation graph

    Why this is correct

    The Investigation graph in Microsoft Sentinel is purpose-built for incident response, rendering an interactive, visual map of entities such as IP addresses, hosts, accounts, and URLs alongside their connected relationships. Analysts can expand nodes to uncover hidden lateral movement, trace the full attack timeline, and pivot between related alerts and bookmarks, which makes it the correct choice for investigating a specific incident. Unlike static lists, the graph dynamically correlates evidence to reveal causal chains and support rapid root-cause analysis.

  • ✗

    Incident dashboard

    Why it's wrong here

    The Incident dashboard (or incidents pane) provides a tabular, filterable list of incidents with metadata such as severity, status, owner, and alert count. While useful for triage and prioritization, it lacks the interactive entity-to-entity graph and temporal visualization needed to reconstruct an attack's path. It cannot show how distinct entities are connected, nor does it support expanding a relationship to see the chronological sequence of activities, so it is unsuitable for in-depth visual investigation.

  • ✗

    Entity behavior analytics (UEBA)

    Why it's wrong here

    Entity behavior analytics (UEBA) in Sentinel, powered by Microsoft's intelligence, builds behavioral baselines for entities and flags anomalies using machine learning—for example, impossible travel or unusual login times. Its purpose is proactive risk detection and threat hunting by surfacing deviations, not to map interactions between entities during a single incident. It does not provide a graph of entity connections or an attack timeline, so it is not the correct tool for investigating the full story of an incident.

  • ✗

    Threat hunting blade

    Why it's wrong here

    The Threat hunting blade in Microsoft Sentinel is designed for proactive, query-driven exploration of raw telemetry using KQL (Kusto Query Language) to search for suspicious patterns across large datasets. It is not incident-centric; it does not open with the entities and alerts already correlated for a specific incident, nor does it render a visual relationship graph. While it can support deeper pivot after an investigation, it is the wrong choice for directly visualizing and exploring a known incident's attack path.

About these practice questions

This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.