hardMultiple Choice
SC-200 Practice Question: A security analyst is investigating a complex…
A security analyst is investigating a complex incident in Microsoft 365 Defender that involves multiple stages: a phishing email, credential theft, and lateral movement. The analyst wants to view a visual representation of the attack chain, showing how alerts and entities are related. Which feature should the analyst use?
⚠ Common exam trap
A common mix-up: candidates confuse the alert timeline (a simple chronological list) with the incident graph (a relational visualization), or they assume Advanced hunting is the only way to correlate events, missing the purpose-built visual tool for attack chain analysis.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Incident graph
The incident graph in Microsoft 365 Defender provides a visual, interactive map of the entire attack chain, linking alerts, entities (such as users, devices, and IPs), and suspicious activities. This allows the analyst to see the progression from the phishing email to credential theft and lateral movement in a single view, making it the correct tool for understanding complex, multi-stage incidents.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Incident graph
Why this is correct
The incident graph is a dedicated visualization feature in Microsoft 365 Defender that maps the entire attack chain as nodes and edges, showing how alerts, entities, and observed events relate to each other. It provides an interactive, graphical representation that lets analysts quickly trace the progression of an attack from initial access to impact, making it the correct choice for understanding complex incident relationships.
- ✗
Advanced hunting
Why it's wrong here
Advanced hunting is a powerful threat-hunting tool that uses Kusto Query Language (KQL) to search raw data across multiple tables for specific indicators or behaviors. However, it is query-based and does not automatically render a visual graph of the attack chain; analysts must interpret the query results themselves, so it cannot replace the incident graph's automatic, graphical depiction of attacker activity.
- ✗
Automated investigation
Why it's wrong here
Automated investigation runs predefined playbooks to collect evidence and execute remediation actions such as containing or removing threats. While it produces detailed reports of the investigation steps and actions taken, it is designed to automate response processes rather than to display a visual, relational graph of how the attack progressed, so it does not meet the need for a graphical attack-chain overview.
- ✗
Alert timeline
Why it's wrong here
The alert timeline presents a chronological list of alerts associated with an incident, helping analysts understand the sequence in which detections occurred. It lacks the graphical connection of related entities and events, showing only time-ordered entries without emphasizing how they relate to one another, so it does not provide the attack-chain relationship mapping that the incident graph offers.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.