Courseiva
hardMultiple Choice

SC-200 Practice Question: A security analyst is investigating a ransomware…

A security analyst is investigating a ransomware attack in Microsoft 365 Defender and needs to understand how the attacker moved laterally from an initial compromised workstation to a domain controller. Which feature should the analyst use to see a visual timeline of device-to-device connections and process executions?

⚠ Common exam trap

Candidates often confuse the single-device Device timeline view (Option A) with the multi-device Incident graph, failing to recognize that lateral movement analysis requires a cross-device perspective, not per-device logs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Incident graph (attack story)

The Incident graph (attack story) in Microsoft 365 Defender provides a visual, interactive timeline that correlates alerts, device-to-device connections, and process executions across the entire attack chain. This allows the analyst to trace lateral movement from the initial compromised workstation to the domain controller in a single, consolidated view, which is exactly what the question requires.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Device timeline view for each affected device

    Why it's wrong here

    The device timeline view in Microsoft Defender for Endpoint presents a chronological, per-device log of events such as process creations, file writes, and network connections. While useful for understanding what happened on one host, it does not show relationships between devices or how an attacker moved from one machine to another. To trace lateral movement, an analyst would have to manually open timelines for every affected device and try to correlate timestamps and network flows, which is slow and error-prone compared to the incident graph's aggregate view.

  • ✓

    Incident graph (attack story)

    Why this is correct

    The incident graph (attack story) in Microsoft Defender XDR (formerly Microsoft 365 Defender) is purpose-built for visualizing the entire attack chain across devices, users, and processes. It automatically aggregates alerts and correlated evidence into a single interactive graph, showing edges that represent connections, logons, or process launches that indicate lateral movement. This gives the analyst an immediate, holistic picture of the ransomware spread without needing to manually piece together data from multiple sources, making it the most efficient choice for this investigation.

  • ✗

    Advanced hunting with DeviceNetworkEvents and DeviceProcessEvents

    Why it's wrong here

    Advanced hunting with DeviceNetworkEvents and DeviceProcessEvents can indeed provide the raw data needed to trace lateral movement, such as outbound connection attempts or remote process executions. However, this approach requires the analyst to write and iterate on KQL queries for each hypothesis, then manually correlate results across devices to reconstruct the attack path. It is a powerful tool for validating specific leads or hunting for unknown variants, but for quickly understanding the big picture of a known incident, the incident graph is faster and less prone to missing context.

  • ✗

    Automated investigation report

    Why it's wrong here

    The automated investigation report summarizes the actions taken by Microsoft Defender's automated investigation and response (AIR), such as quarantining files, disabling scheduled tasks, or terminating processes. It provides a post-hoc record of remediation steps and findings, but it does not offer a visual or interactive representation of the lateral movement between devices. The report focuses on what was done in response to the incident, not on mapping the full path of attacker activity, so it lacks the necessary detail for tracing the ransomware's spread.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.