SC-200 Manage a security operations environment Practice Question
As a security operations analyst, you receive an alert from Microsoft Defender for Identity about a suspicious Kerberos activity. You need to investigate the alert and determine if it is a true positive. What should you use to pivot from the alert to the related user and device timeline?
⚠ Common exam trap
Test-takers frequently assume they need to use a separate tool like Microsoft Sentinel or Microsoft Entra ID audit logs for deeper investigation, but the exam tests the knowledge that the Microsoft 365 Defender portal provides a built-in, integrated timeline for direct pivoting from Defender for Identity alerts.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
From the Microsoft 365 Defender portal, open the alert and click on the user or device name to view their timeline.
In the Microsoft 365 Defender portal, when you open a Microsoft Defender for Identity alert, you can directly click on the user or device name to pivot to their timeline. This timeline provides a consolidated view of activities, including Kerberos events, authentication attempts, and other related signals, enabling you to quickly assess whether the suspicious Kerberos activity is a true positive without leaving the portal.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Search for the user in Microsoft Entra ID audit logs.
Why it's wrong here
Microsoft Entra ID audit logs capture operations performed in Microsoft Entra ID itself, such as application registrations, conditional access policy changes, and Microsoft Entra ID sign-ins. A Defender for Identity alert, however, originates from sensors on your on-premises Active Directory domain controllers and reflects behaviors like Kerberos anomalies, DCSync attempts, or lateral movement using NTLM/Kerberoasting. Those activities never appear in Microsoft Entra ID audit logs, so searching there would return no relevant evidence and would waste time during an active investigation.
- ✗
Open the alert in Microsoft Sentinel and use the investigation graph.
Why it's wrong here
Defender for Identity alerts are generated in the Microsoft 365 Defender platform and are only optionally forwarded to Microsoft Sentinel via a data connector if you have that ingestion configured. Even when the alert is present in Sentinel, the investigation graph in Sentinel is designed for correlating security incidents across multiple ingested data sources, not for directly opening the rich, pre-correlated entity timeline that Defender for Identity maintains. Going to Sentinel first adds unnecessary delay and can miss context that is immediately available in the M365 Defender portal's native alert investigation experience.
- ✓
From the Microsoft 365 Defender portal, open the alert and click on the user or device name to view their timeline.
Why this is correct
The Microsoft 365 Defender portal is the native home for Defender for Identity alerts, and the alert page includes a direct link to the affected user's or device's entity page. Clicking that name opens a comprehensive timeline of that entity's activities, including LDAP queries, Kerberos ticket requests, remote logons, directory object modifications, and any other related security alerts. This timeline lets you quickly trace the attack chain, determine the full blast radius, and pivot to associated resources without having to manually query other logs or export data.
- ✗
Use the Microsoft 365 compliance portal to run an eDiscovery search.
Why it's wrong here
eDiscovery in the Microsoft 365 compliance portal is a legal-hold and investigation tool designed to search and export content from Exchange Online, SharePoint Online, OneDrive for Business, and Teams for legal proceedings or compliance requests. It does not query Active Directory domain controller traffic or Defender for Identity signals such as ticket-granting-ticket activity, SMB/NTLM events, or honeytoken authentication failures. Using eDiscovery for a live security alert would be both ineffective and operationally inappropriate, as it is not optimized for real-time threat hunting or timeline reconstruction.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.