Courseiva
easyMultiple Choice

SC-200 Practice Question: A security analyst is investigating a ransomware…

A security analyst is investigating a ransomware incident in Microsoft 365 Defender. The analyst wants to see a timeline of all actions performed on a specific device, including file creation, registry modifications, and network connections, in chronological order. Which feature should the analyst use?

⚠ Common exam trap

A common mix-up: candidates confuse the chronological event view of the Device timeline with the query-based flexibility of Advanced hunting, but the question specifically asks for a pre-built timeline without requiring custom queries.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Device timeline

The Device timeline in Microsoft Defender for Endpoint provides a chronological view of all events and actions on a specific device, including file creation, registry modifications, and network connections. This feature is specifically designed for forensic investigation of incidents like ransomware, offering a time-ordered list of activities without requiring custom queries.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Device timeline

    Why this is correct

    Device timeline aggregates all recorded events for a device — process executions, file creation, registry modifications and network connections — into one chronological view, letting the analyst reconstruct the ransomware's sequence of actions without querying each event table separately.

  • ✗

    Advanced hunting

    Why it's wrong here

    Advanced hunting runs custom KQL queries across tables, returning matching records rather than a merged chronological view of one device's activity. The device timeline page aggregates file, registry and network events in sequence. Advanced hunting suits proactive threat hunting across the estate, not per-device chronological reconstruction.

  • ✗

    Incident graph

    Why it's wrong here

    The incident graph maps related alerts, entities and evidence across an incident to show relationships, not a chronological sequence of actions on one device. A device timeline is needed for ordered file, registry and network events. The incident graph suits understanding blast radius and alert correlation.

  • ✗

    Action center

    Why it's wrong here

    Action center lists pending and completed remediation actions across devices, not a per-device chronological event history. It is tempting because it aggregates response activity, but it omits file, registry and network events. The device timeline page provides that ordered forensic view.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.