easyMultiple ChoiceObjective-mapped
SC-200 Practice Question: A security analyst is investigating a ransomware…
A security analyst is investigating a ransomware incident in Microsoft 365 Defender. The analyst wants to see a timeline of all actions performed on a specific device, including file creation, registry modifications, and network connections, in chronological order. Which feature should the analyst use?
⚠ Common exam trap
A common mix-up: candidates confuse the chronological event view of the Device timeline with the query-based flexibility of Advanced hunting, but the question specifically asks for a pre-built timeline without requiring custom queries.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Device timeline
The Device timeline in Microsoft Defender for Endpoint provides a chronological view of all events and actions on a specific device, including file creation, registry modifications, and network connections. This feature is specifically designed for forensic investigation of incidents like ransomware, offering a time-ordered list of activities without requiring custom queries.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Device timeline
Why this is correct
The device timeline displays a chronological sequence of events that occurred on a specific device, allowing analysts to trace attack activities.
- ✗
Advanced hunting
Why it's wrong here
Advanced hunting is a query-based tool for proactively hunting threats; it does not provide a pre-built chronological timeline but can be used to reconstruct events manually.
- ✗
Incident graph
Why it's wrong here
The incident graph visualizes how alerts and entities are related within an incident, not a device-specific event timeline.
- ✗
Action center
Why it's wrong here
The Action center lists remediation actions taken or pending, not the full event history.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 209 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.