SC-200 Respond to security incidents Practice Question
During an incident investigation in Microsoft Sentinel, you need to gather related events from multiple data sources into a single view for analysis. Which feature should you use?
⚠ Common exam trap
Watch out — candidates often confuse the Investigation graph with Workbooks or the Logs blade, mistakenly thinking that any visualization or query tool can serve the same purpose, but the Investigation graph is the only feature purpose-built for interactive, entity-centric incident exploration in Sentinel.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Investigation graph
The Investigation graph in Microsoft Sentinel is specifically designed to visually correlate and explore related entities and events across multiple data sources within a single investigation. It allows you to pivot from an alert or entity to see connected users, hosts, IP addresses, and other events, providing a unified view for analysis. This feature directly addresses the need to gather related events from disparate sources into one cohesive view during incident response.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Workbooks
Why it's wrong here
Workbooks in Microsoft Sentinel are interactive dashboards powered by KQL queries, designed for ongoing monitoring and reporting across many incidents over time. They aggregate data into visual summaries but lack the entity-level, case-specific drill-down capabilities needed for ad-hoc investigation of a single incident's relationships and timeline.
- ✓
Investigation graph
Why this is correct
The Investigation graph is the correct tool for incident investigation because it presents an interactive, visual map of entities (such as hosts, IPs, and accounts) and their connections to alerts and activities. It allows analysts to expand nodes to explore related entities, assess blast radius, and pivot directly into other data sources, making it purpose-built for correlating and understanding a specific incident's scope.
- ✗
Watchlists
Why it's wrong here
Watchlists are file-based lookup tables in Sentinel that store custom CSV data for enrichment, such as high-value asset lists or known-bad IPs. While they can be referenced in queries to add context, they do not provide any visual, correlated view of an incident's entities or relationships, so they are not suitable for guiding an analyst through investigation.
- ✗
Logs blade
Why it's wrong here
The Logs blade is a standalone KQL query interface that returns raw tabular results from Log Analytics workspaces. It offers no built-in entity correlation, timeline rendering, or visual graph view, forcing the analyst to manually join and map data across different tables—an impractical and error-prone method for quickly understanding an entire incident.
- ✗
Analytics rules
Why it's wrong here
Analytics rules are detection mechanisms that use scheduled queries, threat intelligence, or Microsoft security insights to generate alerts and incidents based on specific conditions. They are responsible for creating the incident but do not provide any post-detection investigation features, so examining an incident requires a different tool like the Investigation graph to analyze its entities and related data.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.