SC-200 Perform threat hunting Practice Question
During a threat hunting exercise, you need to pivot from a suspicious IP address to find all related alerts and incidents in Microsoft Sentinel. Which feature should you use?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Investigation graph
The investigation graph in Microsoft Sentinel allows visual pivoting and exploration of entities, making it the correct tool for pivoting from a suspicious IP to find related alerts and incidents. Option A (Workbooks) is incorrect because workbooks are for creating dashboards and reports. Option B (Incidents blade) is incorrect because it shows incidents but does not provide entity relationship visualization. Option D (Playbook) is incorrect because playbooks automate responses, not pivot investigations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Workbook
Why it's wrong here
Workbooks in Microsoft Sentinel are interactive dashboards built on Azure Monitor Workbooks. They surface query results from Log Analytics as charts and tables, but they are not designed for entity-level pivoting. Selecting an IP inside a workbook will not automatically expand to related alerts and incidents; pivoting requires an entity graph or a new KQL query against the SuspiciousIP entity.
- ✗
Incidents blade
Why it's wrong here
The Incidents blade is a list view that groups related alerts into incident records and displays severity, status, and assigned entities. Selecting an incident opens its details, but the blade itself does not expand an IP entity across multiple incidents or reveal hidden relationships. To pivot from a suspicious IP you need to launch the entity's investigation graph rather than simply browse the incident list.
- ✓
Investigation graph
Why this is correct
The Investigation graph is Microsoft Sentinel's entity-centric exploration tool, modeling relationships between IPs, hosts, accounts, and alerts as a visual map. From a suspicious IP entity you can double-click or expand to immediately surface all connected alerts, related incidents, and adjacent entities, making it the correct pivot path for threat hunting. It leverages the entity schema and graph data to show both direct and indirect connections.
- ✗
Playbook
Why it's wrong here
Playbooks are automated incident-response workflows in Microsoft Sentinel, built on Azure Logic Apps. They execute predefined actions like enrichment, blocking, or notifications in response to alerts, not for ad-hoc investigation. While a playbook could call a threat-intel API to add context to an IP, it does not give an analyst a visual way to pivot from that IP to all related alerts and incidents in the portal.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.