Courseiva

SC-200 Manage a security operations environment Practice Question

As a SOC analyst, you need to quickly identify if a specific user account has been involved in any incidents in the past week. Which feature in Microsoft Sentinel allows you to search for user-related incidents?

⚠ Common exam trap

Microsoft often tests the misconception that the Incidents blade (Option A) is sufficient for user-specific searches, but the trap is that it lacks entity-level filtering, requiring analysts to manually correlate users across incidents, whereas the Entity behavior blade provides a consolidated user-centric view.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Entity behavior blade

The Entity behavior blade in Microsoft Sentinel provides a user-centric view that aggregates all incidents, alerts, and activities associated with a specific user account. By selecting a user entity and navigating to the 'Incidents' tab within the blade, you can quickly filter incidents involving that user over a defined time range, such as the past week. This feature is designed specifically for investigating user-related security events without needing to write custom queries.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Incidents blade with time range filter

    Why it's wrong here

    The Incidents blade is organized around alert aggregation into incidents and supports filters for time range, status, and severity, but it does not provide a direct filter by entity such as a user name or device ID. Narrowing the time window only limits the temporal scope; you would then have to manually open and inspect each incident's evidence to find a specific user, making this an indirect and inefficient path. Incorrect.

  • ✗

    Hunting blade with user query

    Why it's wrong here

    The Hunting blade is a query workspace for raw Advanced Hunting (KQL) against tables such as IdentityLogonEvents, DeviceEvents, and AlertEvidence, not a summary of incident records. A user query like '| where AccountName == "user"' returns matching raw events, not incidents, and while you could join to IncidentInfo tables, that requires manual query construction rather than an out-of-the-box, entity-centric incident history view. Incorrect.

  • ✓

    Entity behavior blade

    Why this is correct

    The Entity behavior blade is the correct feature because when you open a specific entity (user, device, or domain) in the Defender portal, the Entity behavior tab automatically renders a timeline of that entity's activities, associated alerts, and incident history. This direct entity-focused view lets an analyst immediately see whether that user was implicated in past incidents without writing any queries or building custom workbooks. Correct.

  • ✗

    Workbooks with KQL query

    Why it's wrong here

    Workbooks in Azure Monitor / Microsoft Defender are Azure-based report templates that can embed KQL queries, but they are designed for custom reporting and monitoring, not for a quick per-entity investigation. Without an already-built workbook parameterized for a user entity, you would have to construct and maintain the KQL yourself, which defeats the purpose of a fast, feature-native lookup. Incorrect.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.