AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel
You are investigating a security incident in Microsoft Sentinel. The incident involves multiple alerts from different data sources. You need to correlate the alerts to determine the full attack chain. Which Microsoft Sentinel feature should you use?
⚠ Common exam trap
Many exam-takers confuse 'incident investigation' with 'analytics rules' or 'workbooks,' thinking that correlation happens at the rule or dashboard level, rather than understanding that investigation is a dedicated post-detection feature for exploring relationships within an incident.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Incident investigation
Incident investigation in Microsoft Sentinel is designed specifically for visualizing and correlating alerts within an incident to reconstruct the full attack chain. It provides a graphical map that links entities (e.g., IP addresses, user accounts, hosts) across alerts from different data sources, enabling you to trace the attacker's path step by step.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Incident investigation
Why this is correct
The Incident investigation view in Microsoft Sentinel opens an interactive graphical map that presents the incident's related alerts, entities, and activities as linked nodes. This tool enables you to trace relationships between hosts, IP addresses, accounts, and security events, revealing the attack path through entity timeline and expansion queries. It is precisely the correlation capability that helps analysts explore how individual alerts combine into an attacker's sequence of actions.
- ✗
Analytics rules
Why it's wrong here
Analytics rules are detection templates or custom KQL queries that produce individual alerts based on thresholds, event patterns, or scheduled runs. They trigger the creation of alerts, but they do not correlate multiple alerts into a single attack story; that correlation is performed by incident investigation using incident grouping and entity relationships. While analytics rules define what generates an alert, they lack the interactive entity-graph exploration needed to trace an attack path.
- ✗
Playbooks
Why it's wrong here
Playbooks are Azure Logic Apps workflows that are invoked by a security alert or incident trigger to execute automated response actions, such as sending emails, blocking IPs, or creating tickets. They consume the outputs of correlation rather than performing it: the playbook starts only after an incident exists, and its logic focuses on remediation, not on analyzing entity relationships or alert linkages.
- ✗
Workbooks
Why it's wrong here
Workbooks in Microsoft Sentinel are built on Azure Monitor Workbooks and provide static or query-driven dashboards, visualizations, and interactive reports for trends and metrics. They aggregate data for human monitoring and executive reporting, but they are not designed to explore the entity-to-entity graph of a specific incident or to correlate alerts into a coherent kill chain, which is the function of the investigation graph.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.