Courseiva

Use the Incident Investigation Graph in Microsoft Sentinel

Your SOC is investigating an incident in Microsoft Sentinel. You need to quickly identify all related alerts and entities across the timeline. What Microsoft Sentinel feature should you use?

Quick Answer

The answer is to open the incident investigation graph in Microsoft Sentinel. This feature is the correct choice because it provides a visual, interactive map that correlates all alerts, entities like users and IP addresses, and their relationships across a single timeline, enabling SOC analysts to instantly see the full scope of an incident without manual data correlation. On the SC-200 exam, this question tests your understanding of incident management workflows, often appearing as a scenario where you must distinguish the investigation graph from tools like the analytics rule wizard or entity behavior analytics—a common trap is confusing it with the hunting blade. For a quick memory tip, think of the investigation graph as your incident’s “relationship map”: if you need to connect dots across time and entities, graph it out.

⚠ Common exam trap

Test-takers frequently confuse the incident investigation graph with the Incident workbook, assuming both provide incident details, but the workbook is for aggregated reporting while the graph is for interactive, entity-level exploration of a single incident.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Open the incident investigation graph.

The incident investigation graph in Microsoft Sentinel provides a visual, interactive map of all alerts, entities (such as users, IP addresses, hosts), and their relationships linked to a specific incident. This allows SOC analysts to quickly see the full scope of an incident across the timeline without manually correlating data, making it the correct tool for this scenario.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Run a hunting query.

    Why it's wrong here

    Hunting queries proactively search raw logs for threats, returning rows you must correlate manually; they do not aggregate an existing incident's alerts and entities. It is tempting because hunting is used to discover unknown threats, but the stem requires reviewing an already-generated incident's linked alerts and entity timeline.

  • ✓

    Open the incident investigation graph.

    Why this is correct

    The investigation graph visually maps alerts, entities and their relationships across the incident timeline, letting analysts pivot through connected evidence. Logs queries and workbooks show data but lack this interactive entity-relationship exploration, so the graph directly satisfies the need to identify all related alerts and entities.

  • ✗

    Review the analytics rule that generated the incident.

    Why it's wrong here

    The analytics rule shows the detection logic that fired, not the aggregated alerts, entities and timeline belonging to this incident. It is tempting because rules define what triggers incidents, and reviewing them is valid when tuning detections, but the stem asks for the incident's related alerts and entities.

  • ✗

    Use the Incident workbook.

    Why it's wrong here

    Incident workbooks display custom reports and visualisations built from queries, not the built-in correlated alert and entity timeline. It is tempting because workbooks visualise incident data, and they would suit bespoke reporting, but the stem needs the native incident investigation view listing related alerts and entities.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SC-200

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Your SOC team receives a high-priority incident related to a potential malware outbreak. You need to quickly identify all affected devices and users across the environment. What Microsoft Defender XDR feature should you use?

easy
  • A.Advanced hunting
  • B.Action center
  • ✓ C.Incident graph
  • D.Microsoft Sentinel workbook

Why C: The incident graph in Microsoft Defender XDR visually maps the relationships between alerts, devices, users, IP addresses, and other entities involved in an incident, letting analysts quickly see the full scope of an outbreak. It aggregates related alerts into a single incident and shows lateral movement, affected users, and affected devices in one view. This is the fastest way to identify all impacted assets and accounts during a high-priority malware incident.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.