Courseiva

SC-200 Manage a security operations environment Practice Question

Which TWO actions can you perform in the Microsoft Defender XDR unified alert queue? (Select TWO.)

⚠ Common exam trap

Test-takers frequently confuse the unified alert queue with the incident queue, mistakenly thinking that actions like running playbooks or editing rules are available directly from the alert queue, when in fact those actions are tied to incidents or separate configuration interfaces.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Link the alert to an existing incident

In the Microsoft Defender XDR unified alert queue, you can link an alert to an existing incident to consolidate related alerts into a single investigation. This action is supported directly from the alert queue interface, allowing analysts to manage incident correlation without leaving the queue. Linking alerts helps reduce alert fatigue and streamlines the incident management workflow.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Link the alert to an existing incident

    Why this is correct

    In the Microsoft Defender XDR alert queue, you can take an alert and associate it with an existing incident by selecting the 'Link to incident' action. This consolidates related alerts into a single incident, allowing the SOC team to manage and investigate the full scope of an attack from one place. The linkage is stored so that the alert's lifecycle becomes tied to the incident's status, ensuring proper tracking and correlation.

  • ✓

    Assign an alert to a SOC analyst

    Why this is correct

    The alert queue supports an 'Assign' action that sets the alert's owner to a specific SOC analyst or a team. This is a fundamental triage function that establishes accountability and allows work to be distributed among team members. Once assigned, the analyst can see the alert in their queue and is expected to carry out the investigation, with the assignment reflected in the alert's metadata and activity history.

  • ✗

    Create a hunting query from the alert details

    Why it's wrong here

    You cannot create a hunting query directly from the alert details pane or the alert queue because hunting queries are authored and saved exclusively in the Advanced hunting workspace using Kusto Query Language (KQL). While the alert may give you a 'Go hunt' link that pre-populates the Advanced hunting editor with relevant query parameters, that action merely opens the editor rather than creating a saved, reusable query. The alert queue itself has no capability for query construction or persistence.

  • ✗

    Edit the analytics rule that generated the alert

    Why it's wrong here

    Editing the analytics rule that produced an alert is not possible from the alert queue because rule logic is managed in the Microsoft Sentinel Analytics blade or the respective security rule configuration page, not in the Defender XDR alert interface. The alert queue only exposes triage operations on the alert itself, such as assignment or linking, and intentionally does not provide access to the detection rule definitions. To change the underlying rule you must navigate to its configuration page and have the appropriate permissions, separate from alert management.

  • ✗

    Run a playbook to automatically remediate the alert

    Why it's wrong here

    Playbooks that automate remediation are not executed directly from the Microsoft Defender XDR alert queue; they are designed to be triggered by Microsoft Sentinel automation rules or incident creation triggers. In the alert queue, the available response actions are limited to those built into Defender XDR, such as device isolation or antivirus scan, rather than custom Logic Apps playbooks. Attempting to run a playbook manually would require navigating to the incident or rule where the playbook is associated, not from the alert itself.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.