SC-200 Manage a security operations environment Practice Question
A SOC analyst receives a high-severity alert for a user who downloaded a malicious file from a phishing email. The analyst needs to quickly assess the scope of the incident across endpoints, email, and identities. Which Microsoft Defender XDR feature should the analyst use to get a unified view of the incident?
⚠ Common exam trap
A common mix-up: candidates confuse the Microsoft Defender XDR incident queue with Microsoft Sentinel incidents, assuming Sentinel is the primary unified view, but the question specifically asks for the Microsoft Defender XDR feature, not a separate SIEM product.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Defender XDR incident queue
The Microsoft Defender XDR incident queue is the correct choice because it aggregates alerts from Microsoft Defender for Endpoint, Office 365, and Identity into a single incident view, enabling the analyst to correlate the malicious file download across endpoints, email, and user identities without switching consoles. This unified incident management is a core feature of Microsoft Defender XDR, designed specifically for rapid triage and scope assessment in multi-domain threats.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Microsoft Defender XDR incident queue
Why this is correct
The Microsoft Defender XDR incident queue is the correct location because it consolidates alerts from Defender for Endpoint, Defender for Identity, Defender for Office 365, Defender for Cloud Apps, and other Microsoft 365 security signals into a single correlated incident. This gives the SOC analyst the full attack story, affected assets, and evidence, along with integrated investigation and response actions. High-severity alerts originating from Microsoft Defender workloads are automatically aggregated here, making it the primary triage and investigation surface.
- ✗
Microsoft Purview compliance portal
Why it's wrong here
The Microsoft Purview compliance portal is exclusively oriented around data governance, records management, insider risk, eDiscovery, and regulatory compliance policies, not live security incident response. It does not ingest or correlate endpoint, identity, or email security alerts from Microsoft Defender, nor does it provide an attack chain or incident timeline. A high-severity security alert would never be queued here for analyst triage, so this option is incorrect.
- ✗
Microsoft Intune device compliance dashboard
Why it's wrong here
While Microsoft Intune provides a device compliance dashboard that shows whether managed devices meet health and configuration policies, it is fundamentally a mobile device management and application management solution, not an incident response workspace. Intune can enforce conditional access and push remediation actions, but it lacks the cross-workload alert correlation, entity timeline, and automated investigation capabilities of the Defender XDR incident queue. High-severity security alerts are not directed to Intune for SOC investigation.
- ✗
Microsoft Sentinel incidents blade
Why it's wrong here
The Microsoft Sentinel incidents blade presents only the incidents that Sentinel has created from its own analytics rules and connected log sources; it is a cloud-native SIEM workbench rather than the unified XDR incident queue. Although Sentinel can ingest Defender alerts via connectors, the incident queue in Microsoft Defender XDR is specifically scoped to the native Microsoft 365 security stack and provides the complete linked alert graph, impacted assets, and automated response actions. Therefore, for a high-severity alert in the Defender XDR service, the analyst should use the Defender XDR incident queue, not the Sentinel blade.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.