You are investigating an incident in Microsoft Defender XDR. The incident involves multiple alerts from different workloads. You need to view all related alerts in a single timeline. What should you use?
The incident page is the central investigation surface in Microsoft Defender XDR. It automatically aggregates all alerts related to a single attack campaign from across the Microsoft 365 security stack—Defender for Endpoint, Defender for Office 365, Defender for Identity, and Defender for Cloud Apps—into a unified view. Along with alerts, it surfaces the full attack story, affected assets, and evidence, making it the correct place to investigate the full scope of an incident. This page directly answers the need to see all related alerts in one place.
Why this answer
The Incident page in Microsoft Defender XDR aggregates all alerts from different workloads (e.g., Microsoft Defender for Endpoint, Office 365, Identity) into a single, unified timeline view. This allows you to see the sequence of events and alerts related to the incident in chronological order, which is essential for understanding the attack chain and coordinating response actions.
Exam trap
The trap here is that candidates confuse the Incident page's unified alert timeline with Advanced hunting, thinking they need to write a KQL query to see related alerts, when in fact the Incident page automatically provides that consolidated view without any querying.
How to eliminate wrong answers
Option B (Advanced hunting) is wrong because it is a query-based tool for proactively searching raw data across workloads, not a pre-built timeline view for a specific incident. Option C (Action center) is wrong because it lists pending and completed remediation actions (e.g., isolate device, block file) across incidents, not the alerts or their timeline for a single incident. Option D (Device timeline) is wrong because it shows events and alerts for a single device only, not the cross-workload alerts aggregated for an incident.