Courseiva
hardMultiple Choice

SC-200 Practice Question: A security analyst is investigating a complex…

A security analyst is investigating a complex incident in Microsoft 365 Defender that involves multiple stages: a phishing email, credential theft, and lateral movement. The analyst wants to view a visual representation of the attack chain, showing how alerts and entities are related. Which feature should the analyst use?

⚠ Common exam trap

A common mix-up: candidates confuse the alert timeline (a simple chronological list) with the incident graph (a relational visualization), or they assume Advanced hunting is the only way to correlate events, missing the purpose-built visual tool for attack chain analysis.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Incident graph

The incident graph in Microsoft 365 Defender provides a visual, interactive map of the entire attack chain, linking alerts, entities (such as users, devices, and IPs), and suspicious activities. This allows the analyst to see the progression from the phishing email to credential theft and lateral movement in a single view, making it the correct tool for understanding complex, multi-stage incidents.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Incident graph

    Why this is correct

    The incident graph is a dedicated visualization feature in Microsoft 365 Defender that maps the entire attack chain as nodes and edges, showing how alerts, entities, and observed events relate to each other. It provides an interactive, graphical representation that lets analysts quickly trace the progression of an attack from initial access to impact, making it the correct choice for understanding complex incident relationships.

  • ✗

    Advanced hunting

    Why it's wrong here

    Advanced hunting is a powerful threat-hunting tool that uses Kusto Query Language (KQL) to search raw data across multiple tables for specific indicators or behaviors. However, it is query-based and does not automatically render a visual graph of the attack chain; analysts must interpret the query results themselves, so it cannot replace the incident graph's automatic, graphical depiction of attacker activity.

  • ✗

    Automated investigation

    Why it's wrong here

    Automated investigation runs predefined playbooks to collect evidence and execute remediation actions such as containing or removing threats. While it produces detailed reports of the investigation steps and actions taken, it is designed to automate response processes rather than to display a visual, relational graph of how the attack progressed, so it does not meet the need for a graphical attack-chain overview.

  • ✗

    Alert timeline

    Why it's wrong here

    The alert timeline presents a chronological list of alerts associated with an incident, helping analysts understand the sequence in which detections occurred. It lacks the graphical connection of related entities and events, showing only time-ordered entries without emphasizing how they relate to one another, so it does not provide the attack-chain relationship mapping that the incident graph offers.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.