SC-200 Manage a security operations environment Practice Question
Which THREE components are part of the Microsoft Defender XDR incident management process?
⚠ Common exam trap
Many candidates confuse the components of the Microsoft Defender XDR incident management process (entities, alerts, evidence) with automation features like playbooks, which belong to Microsoft Sentinel, not Defender XDR.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Entities
Entities are a core component of the Microsoft Defender XDR incident management process because they represent the assets (such as users, devices, mailboxes, and applications) that are involved in an incident. The incident graph automatically links related entities to provide a unified view of the attack story, enabling analysts to pivot from an alert to the affected resources for investigation and response.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Entities
Why this is correct
Entities are the discrete actors, assets, and resources involved in an incident—such as user accounts, devices, IP addresses, and mailboxes. In the Microsoft Defender XDR incident data model, these are not just attached labels; they are contextualized and linked to alerts and evidence to establish the attack's scope and blast radius. This makes them a foundational component for threat hunting and investigation because they, unlike alerts or evidence, represent the 'who' and 'what' that are impacted.
- ✓
Alerts
Why this is correct
Alerts are individual detection signals generated by Defender XDR's various workloads, such as Defender for Endpoint, Defender for Office 365, or Defender for Identity. During incident creation, the platform automatically correlates and aggregates these alerts into a single incident based on the attack story, timelines, and entities—making the incident a higher-level representation of the entire threat. Alerts capture the 'when' and 'how' of the attack sequence, but they do not by themselves include the rich forensic artifacts or the involved actor definitions that entities and evidence provide.
- ✗
User settings
Why it's wrong here
User settings—such as timezone, locale, notification preferences, and portal layout customizations—are personalization options for the Microsoft Defender portal interface. These are configuration-level data stored per user account and have no place within the incident data schema, which strictly defines the logical grouping of alerts, entities, and evidence. Treating user settings as a component of an incident would conflate the administrative layer of the product with the security data model, which is concerned only with threat-related information.
- ✗
Playbooks
Why it's wrong here
Playbooks are orchestrated automation workflows, but they are a native feature of Microsoft Sentinel, not part of the core Microsoft Defender XDR incident structure. In Defender XDR, automated remediation is achieved through built-in Automated Investigation and Response (AIR) capabilities or by integrating with external tools like Logic Apps—but these are not components that make up an incident. This distinction is important because while Sentinel playbooks can be triggered by Defender XDR incidents via connectors, the incident's internal anatomy remains composed only of alerts, entities, and evidence.
- ✓
Evidence
Why this is correct
Evidence comprises the concrete forensic artifacts linked to an incident, including files, process trees, registry keys, scheduled tasks, and network connections that were observed during the attack. These items are collected and preserved from the underlying alerts and are directly referenced from the incident to provide raw, defensible data for investigation. Evidence differs from entities in that it focuses on the malicious or anomalous happenings themselves, rather than the identities or devices involved, and it differs from alerts by being the actual data points rather than the detection signals.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.