easyMultiple Choice
SC-200 Alerts tab Practice Question
A security analyst in Microsoft 365 Defender is investigating an incident that contains multiple alerts from different sources (e.g., Microsoft Defender for Endpoint, Microsoft 365 Defender for Office). The analyst wants to see a consolidated list of all alerts associated with the incident, including their severity, status, and detection source. Which tab within the incident details page should the analyst use?
⚠ Common exam trap
Watch out — candidates often confuse the entity-specific tabs (Devices, Users, Mailboxes) with the alert-centric view, mistakenly thinking those tabs also show alert metadata, but they only show associated entities and their properties, not the consolidated alert list with severity and detection source.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Alerts tab
The Alerts tab on the incident details page in Microsoft 365 Defender provides a consolidated, filterable list of all alerts linked to the incident, regardless of their source (e.g., Microsoft Defender for Endpoint, Microsoft Defender for Office 365). This tab displays each alert's severity, status, and detection source, allowing the analyst to triage and correlate alerts from different workloads in a single view. The other tabs focus on specific entities (devices, users, mailboxes) rather than the unified alert list.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Alerts tab
Why this is correct
The Alerts tab consolidates every alert linked to the incident, showing severity, status and detection source across Defender for Endpoint and Office. This gives the analyst the unified alert list the investigation requires without switching portals.
- ✗
Devices tab
Why it's wrong here
The Devices tab enumerates affected endpoints and their investigation data, not the alerts raised across sources with severity and status. It is tempting because device timelines help trace lateral movement, but the requested consolidated alert inventory is presented on the Alerts tab.
- ✗
Users tab
Why it's wrong here
The Users tab lists the accounts involved in the incident, not the alerts themselves, so it cannot show severity, status or detection source per alert. It is tempting because user context matters when scoping impact, but the consolidated alert list lives on the Alerts tab.
- ✗
Mailboxes tab
Why it's wrong here
The Mailboxes tab shows email-related entities and their remediation state, not a cross-source alert list with severity, status and detection source. It is tempting because Office alerts often involve mailboxes, but the consolidated alert inventory is displayed on the Alerts tab.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.