SC-200 Manage a security operations environment Practice Question
Which TWO actions can you perform in the Microsoft Defender XDR unified alert queue? (Select TWO.)
⚠ Common exam trap
Test-takers frequently confuse the unified alert queue with the incident queue, mistakenly thinking that actions like running playbooks or editing rules are available directly from the alert queue, when in fact those actions are tied to incidents or separate configuration interfaces.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Link the alert to an existing incident
In the Microsoft Defender XDR unified alert queue, you can link an alert to an existing incident to consolidate related alerts into a single investigation. This action is supported directly from the alert queue interface, allowing analysts to manage incident correlation without leaving the queue. Linking alerts helps reduce alert fatigue and streamlines the incident management workflow.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Link the alert to an existing incident
Why this is correct
In the Microsoft Defender XDR alert queue, you can take an alert and associate it with an existing incident by selecting the 'Link to incident' action. This consolidates related alerts into a single incident, allowing the SOC team to manage and investigate the full scope of an attack from one place. The linkage is stored so that the alert's lifecycle becomes tied to the incident's status, ensuring proper tracking and correlation.
- ✓
Assign an alert to a SOC analyst
Why this is correct
The alert queue supports an 'Assign' action that sets the alert's owner to a specific SOC analyst or a team. This is a fundamental triage function that establishes accountability and allows work to be distributed among team members. Once assigned, the analyst can see the alert in their queue and is expected to carry out the investigation, with the assignment reflected in the alert's metadata and activity history.
- ✗
Create a hunting query from the alert details
Why it's wrong here
You cannot create a hunting query directly from the alert details pane or the alert queue because hunting queries are authored and saved exclusively in the Advanced hunting workspace using Kusto Query Language (KQL). While the alert may give you a 'Go hunt' link that pre-populates the Advanced hunting editor with relevant query parameters, that action merely opens the editor rather than creating a saved, reusable query. The alert queue itself has no capability for query construction or persistence.
- ✗
Edit the analytics rule that generated the alert
Why it's wrong here
Editing the analytics rule that produced an alert is not possible from the alert queue because rule logic is managed in the Microsoft Sentinel Analytics blade or the respective security rule configuration page, not in the Defender XDR alert interface. The alert queue only exposes triage operations on the alert itself, such as assignment or linking, and intentionally does not provide access to the detection rule definitions. To change the underlying rule you must navigate to its configuration page and have the appropriate permissions, separate from alert management.
- ✗
Run a playbook to automatically remediate the alert
Why it's wrong here
Playbooks that automate remediation are not executed directly from the Microsoft Defender XDR alert queue; they are designed to be triggered by Microsoft Sentinel automation rules or incident creation triggers. In the alert queue, the available response actions are limited to those built into Defender XDR, such as device isolation or antivirus scan, rather than custom Logic Apps playbooks. Attempting to run a playbook manually would require navigating to the incident or rule where the playbook is associated, not from the alert itself.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.