Courseiva
easyMultiple Choice

SC-200 Practice Question: A security analyst is reviewing an incident in…

A security analyst is reviewing an incident in Microsoft 365 Defender where malware was detected on multiple endpoints. The analyst wants to see a visual representation of the attack progression, including the initial entry point and all affected devices. Which feature in the Microsoft 365 Defender portal should the analyst use?

⚠ Common exam trap

Test-takers frequently confuse the incident graph (visual attack path) with Advanced hunting (raw data querying) because both are used for investigation, but only the graph provides a pre-built visual map of the attack progression.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Incident graph

The incident graph in Microsoft 365 Defender provides a visual, interactive map of the entire attack progression, showing the initial entry point, lateral movement, and all affected devices and users. It correlates alerts and evidence into a single timeline, enabling the analyst to understand the full scope of the incident at a glance. This directly meets the requirement for a visual representation of the attack progression.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Incident graph

    Why this is correct

    The Incident graph is correct because Microsoft 365 Defender automatically assembles a visual map of the entire attack chain for the selected incident. It displays related alerts, affected users, devices, and suspicious entities as connected nodes, with edges representing the sequence of events and relationships. This pre-built, interactive graph gives analysts an immediate high-level attack narrative without requiring custom queries.

  • ✗

    Advanced hunting

    Why it's wrong here

    Advanced hunting is wrong because it is a Kusto Query Language (KQL)-based tool designed for ad-hoc, custom threat hunting across raw, schema-normalized tables. It does not provide a pre-built visual attack story; instead, an analyst must manually write and execute queries to surface indicators or relationships, and the results are returned as tabular data rather than an incident-specific graphical attack chain.

  • ✗

    Threat analytics

    Why it's wrong here

    Threat analytics is wrong because it is a threat-intelligence solution that aggregates global research on known adversaries, active campaigns, vulnerabilities, and recommended mitigations. It provides broad, contextual reporting across the threat landscape rather than a visualization of a specific incident's lifecycle. Consequently, while it may help an analyst understand the attacker's TTPs, it does not map the progression of entities and events for the particular incident under review.

  • ✗

    Action center

    Why it's wrong here

    Action center is wrong because it is the operational hub for tracking and approving remediation actions such as antivirus scans, device isolation, and file quarantines that were initiated manually or automatically. It lists pending and completed tasks with their status, but it does not illustrate how the attack unfolded or how different entities relate to one another over time. The Action center supports incident response, yet it is not a visual attack narrative.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.