hardMultiple Select
SC-200 Practice Question: A Microsoft Sentinel incident contains alerts…
A Microsoft Sentinel incident contains alerts from multiple analytics rules. The analyst suspects the same compromised account performed impossible travel followed by suspicious mailbox access. Which two actions best help correlate identity and mailbox activity?
⚠ Common exam trap
Candidates often think deleting or disabling rules will fix the correlation gap, but the correct approach is to manually query the relevant data sources (SigninLogs and OfficeActivity) to perform the correlation, as Sentinel does not automatically link identity and mailbox events across different data connectors.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Query SigninLogs for the account around the alert timestamps
Querying SigninLogs for the account around the alert timestamps directly retrieves Microsoft Entra ID authentication events, which are essential for identifying the source IP addresses, locations, and timestamps that define the impossible travel pattern. This data is the primary evidence for the first part of the suspected compromise.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Query SigninLogs for the account around the alert timestamps
Why this is correct
Querying SigninLogs provides critical identity context: each authentication event records timestamp, source IP, user agent, risk level, and applied conditional access policies. By filtering this table for the account around the alert timestamps, an analyst can determine whether the account actually authenticated during the alert's activity window and from which location, directly linking the alerts to a known sign-in session. This correlation is fundamental for validating whether the alerts represent genuine account compromise or a false positive triggered by a legitimate user action.
- ✗
Delete the incident to force it to regenerate
Why it's wrong here
Deleting the incident does not force any regeneration—it merely removes the incident record from the workspace while the underlying alert data remains in the relevant tables. Incident deletion is a destructive and irreversible action that destroys the UI-based correlation context, and no analytics rule or data ingestion pipeline is triggered by deletion to re-create the incident. This action provides zero investigative value and potentially harms the security team's ability to perform later forensic review, making it an absurd response to an investigation need.
- ✗
Disable all analytics rules that contributed alerts
Why it's wrong here
Disabling all contributing analytics rules is a broad, reactive configuration change that stops future alert generation but does nothing to reconcile the alerts already collected. It reduces security visibility across the environment by leaving dangerous activity unmonitored, and it may violate compliance or detection coverage requirements. The investigation demands analyzing and correlating the existing alerts to understand the attack chain; disabling rules is an unrelated, counterproductive action that does not answer the question of what the account did or whether the incident is genuine.
- ✓
Query OfficeActivity or relevant Microsoft 365 Defender email/cloud activity tables for mailbox operations
Why this is correct
Microsoft 365 Defender's EmailEvents, EmailActions, and CloudAppEvents tables, along with OfficeActivity, reveal what the authenticated account actually did after sign-in—email reads, mailbox searches, file downloads, or admin actions. Joining these with SigninLogs on the user principal name and a shared time window provides an end-to-end narrative, from authentication to specific operations. This helps confirm whether the alerts are justified by observed post-authentication activity and distinguishes legitimate behavior from malicious actions like mass mailbox exfiltration or data theft.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.