Courseiva
Perform threat hunting →easyMultiple Choice

SC-200 Perform threat hunting Practice Question

During a threat hunting exercise, you need to pivot from a suspicious IP address to find all related alerts and incidents in Microsoft Sentinel. Which feature should you use?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Investigation graph

The investigation graph in Microsoft Sentinel allows visual pivoting and exploration of entities, making it the correct tool for pivoting from a suspicious IP to find related alerts and incidents. Option A (Workbooks) is incorrect because workbooks are for creating dashboards and reports. Option B (Incidents blade) is incorrect because it shows incidents but does not provide entity relationship visualization. Option D (Playbook) is incorrect because playbooks automate responses, not pivot investigations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Workbook

    Why it's wrong here

    Workbooks in Microsoft Sentinel are interactive dashboards built on Azure Monitor Workbooks. They surface query results from Log Analytics as charts and tables, but they are not designed for entity-level pivoting. Selecting an IP inside a workbook will not automatically expand to related alerts and incidents; pivoting requires an entity graph or a new KQL query against the SuspiciousIP entity.

  • ✗

    Incidents blade

    Why it's wrong here

    The Incidents blade is a list view that groups related alerts into incident records and displays severity, status, and assigned entities. Selecting an incident opens its details, but the blade itself does not expand an IP entity across multiple incidents or reveal hidden relationships. To pivot from a suspicious IP you need to launch the entity's investigation graph rather than simply browse the incident list.

  • ✓

    Investigation graph

    Why this is correct

    The Investigation graph is Microsoft Sentinel's entity-centric exploration tool, modeling relationships between IPs, hosts, accounts, and alerts as a visual map. From a suspicious IP entity you can double-click or expand to immediately surface all connected alerts, related incidents, and adjacent entities, making it the correct pivot path for threat hunting. It leverages the entity schema and graph data to show both direct and indirect connections.

  • ✗

    Playbook

    Why it's wrong here

    Playbooks are automated incident-response workflows in Microsoft Sentinel, built on Azure Logic Apps. They execute predefined actions like enrichment, blocking, or notifications in response to alerts, not for ad-hoc investigation. While a playbook could call a threat-intel API to add context to an IP, it does not give an analyst a visual way to pivot from that IP to all related alerts and incidents in the portal.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.