Courseiva

SC-200 Manage a security operations environment Practice Question

Which THREE components are part of the Microsoft Defender XDR incident management process?

⚠ Common exam trap

Many candidates confuse the components of the Microsoft Defender XDR incident management process (entities, alerts, evidence) with automation features like playbooks, which belong to Microsoft Sentinel, not Defender XDR.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Entities

Entities are a core component of the Microsoft Defender XDR incident management process because they represent the assets (such as users, devices, mailboxes, and applications) that are involved in an incident. The incident graph automatically links related entities to provide a unified view of the attack story, enabling analysts to pivot from an alert to the affected resources for investigation and response.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Entities

    Why this is correct

    Entities are the discrete actors, assets, and resources involved in an incident—such as user accounts, devices, IP addresses, and mailboxes. In the Microsoft Defender XDR incident data model, these are not just attached labels; they are contextualized and linked to alerts and evidence to establish the attack's scope and blast radius. This makes them a foundational component for threat hunting and investigation because they, unlike alerts or evidence, represent the 'who' and 'what' that are impacted.

  • ✓

    Alerts

    Why this is correct

    Alerts are individual detection signals generated by Defender XDR's various workloads, such as Defender for Endpoint, Defender for Office 365, or Defender for Identity. During incident creation, the platform automatically correlates and aggregates these alerts into a single incident based on the attack story, timelines, and entities—making the incident a higher-level representation of the entire threat. Alerts capture the 'when' and 'how' of the attack sequence, but they do not by themselves include the rich forensic artifacts or the involved actor definitions that entities and evidence provide.

  • ✗

    User settings

    Why it's wrong here

    User settings—such as timezone, locale, notification preferences, and portal layout customizations—are personalization options for the Microsoft Defender portal interface. These are configuration-level data stored per user account and have no place within the incident data schema, which strictly defines the logical grouping of alerts, entities, and evidence. Treating user settings as a component of an incident would conflate the administrative layer of the product with the security data model, which is concerned only with threat-related information.

  • ✗

    Playbooks

    Why it's wrong here

    Playbooks are orchestrated automation workflows, but they are a native feature of Microsoft Sentinel, not part of the core Microsoft Defender XDR incident structure. In Defender XDR, automated remediation is achieved through built-in Automated Investigation and Response (AIR) capabilities or by integrating with external tools like Logic Apps—but these are not components that make up an incident. This distinction is important because while Sentinel playbooks can be triggered by Defender XDR incidents via connectors, the incident's internal anatomy remains composed only of alerts, entities, and evidence.

  • ✓

    Evidence

    Why this is correct

    Evidence comprises the concrete forensic artifacts linked to an incident, including files, process trees, registry keys, scheduled tasks, and network connections that were observed during the attack. These items are collected and preserved from the underlying alerts and are directly referenced from the incident to provide raw, defensible data for investigation. Evidence differs from entities in that it focuses on the malicious or anomalous happenings themselves, rather than the identities or devices involved, and it differs from alerts by being the actual data points rather than the detection signals.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.