Courseiva

SC-200 Respond to security incidents Practice Question

A SOC team uses Microsoft Sentinel with Microsoft Defender XDR integration. An incident is created from a Defender for Endpoint alert. The analyst wants to run a KQL query across all affected devices without creating a new analytics rule. How can the analyst achieve this?

⚠ Common exam trap

Watch out — candidates often confuse the Hunting blade (which is for proactive, scheduled queries) with the incident-specific Logs blade (which is for reactive, ad-hoc investigation), leading them to choose option C incorrectly.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use the incident's Logs blade to run a KQL query.

The incident's Logs blade in Microsoft Sentinel allows analysts to run KQL queries directly against the data ingested into the workspace, scoped to the incident's context. This enables ad-hoc investigation across all affected devices without modifying or creating any analytics rules, which would require rule authoring and deployment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Modify the analytics rule that created the incident.

    Why it's wrong here

    Modifying the analytics rule that created the incident changes the detection logic for all future matching activity, potentially suppressing legitimate detections or altering severity scoring. It does nothing to investigate the already generated incident's evidence, timelines, or entities, and it introduces a configuration change that should be handled separately from the investigative workflow.

  • ✓

    Use the incident's Logs blade to run a KQL query.

    Why this is correct

    The incident's Logs blade opens a query environment scoped to the underlying Log Analytics workspace, allowing you to run KQL to pivot on entities, timestamps, or raw tables without creating or altering any rule. This ad-hoc query capability is the appropriate tool for investigating an existing incident because it gives immediate, context-aware access to the telemetry relevant to that incident.

  • ✗

    Use the Microsoft Sentinel Hunting blade.

    Why it's wrong here

    The Hunting blade is built for proactive threat hunting—running queries across the workspace to discover suspicious activity that has not yet triggered alerts—and is not scoped to any specific incident. To use it for a current incident, you would have to manually reconstruct the incident's entity values and time range from memory, and you would lose the incident context such as linked alerts, bookmarks, and comments that the incident's own workflow provides.

  • ✗

    Create a new workbook.

    Why it's wrong here

    Workbooks are interactive dashboards designed for persistent, repeatable reporting and monitoring, not for ad-hoc incident investigation. Creating a new workbook to answer a one-off investigative question requires authoring, query organization, and visualization steps that add overhead, whereas the Logs blade provides an immediate query sandbox without any persistent artifact.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.