Courseiva

SC-200 Respond to security incidents Practice Question

A security analyst in your SOC is investigating a Microsoft Defender XDR incident. The analyst wants to see a visual representation of the attack timeline and related entities across emails, devices, and identities. Which feature should the analyst use?

⚠ Common exam trap

Candidates often confuse the incident graph with advanced hunting or other investigation tools; the incident graph is specifically for visual incident visualization in Defender XDR.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Incident graph in Microsoft Defender XDR.

The incident graph in Microsoft Defender XDR is designed to provide a visual, interactive representation of an incident, showing the relationships between entities like users, devices, mailboxes, and the timeline of events. It aggregates alerts from multiple Defender workloads, enabling analysts to quickly understand the attack's scope. Advanced hunting is query-based, Sentinel's graph is separate, and Defender for Cloud Apps activity log is app-focused. The incident graph directly fulfills the need for a visual attack timeline and entity mapping.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Microsoft Sentinel incident investigation graph.

    Why it's wrong here

    Microsoft Sentinel has an investigation graph, but the scenario specifies a Microsoft Defender XDR incident. While Sentinel can ingest Defender XDR incidents, the native incident graph in Defender XDR is the direct feature for visualizing entities and timeline within that portal. Using Sentinel would require additional configuration and may not show the same integrated view.

  • ✗

    Advanced hunting in Microsoft Defender XDR.

    Why it's wrong here

    Advanced hunting allows querying raw data using Kusto Query Language (KQL) to find threats, but it does not provide a visual attack timeline or entity relationship graph. It is a powerful tool for proactive hunting, not for visual incident investigation. The scenario asks for a visual representation, which advanced hunting does not offer.

  • ✓

    Incident graph in Microsoft Defender XDR.

    Why this is correct

    The incident graph in Microsoft Defender XDR provides a visual representation of the attack timeline and relationships between entities such as users, devices, and emails. It helps analysts understand the scope and progression of an attack across multiple workloads. This is the correct feature for the described requirement.

  • ✗

    Microsoft Defender for Cloud Apps activity log.

    Why it's wrong here

    The activity log in Microsoft Defender for Cloud Apps shows user activities and file events in cloud applications, but it does not provide a cross-workload visual attack timeline for an incident. It is focused on cloud app security and does not integrate device and email entities in a graph. Not the right tool for the requirement.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.