SC-200 Respond to security incidents Practice Question
Which TWO are valid sources of evidence in a Microsoft Sentinel incident? (Choose two.)
⚠ Common exam trap
Candidates often confuse 'sources of evidence' with 'tools used during investigation'—playbooks and hunting queries are actions or workflows, not static evidence records stored within the incident.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Alerts
Alerts are a core evidence type in Microsoft Sentinel incidents because they represent the raw security findings that trigger an incident. When an alert is generated from a detection rule (e.g., analytics rule, fusion, or scheduled query), it is automatically linked to the incident as evidence, providing the initial context and supporting data for investigation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Playbooks
Why it's wrong here
Playbooks are cloud-based automated response workflows in Microsoft Sentinel, typically built on Azure Logic Apps. They can be invoked during incident handling to perform actions such as sending emails, creating tickets, or blocking IPs, but the workflow itself is not a data record or investigation artifact. Evidence must capture a detection, a search result, or an entity observation; a playbook's automation steps do not meet that definition. Therefore, playbooks are not considered valid sources of evidence.
- ✗
Watchlists
Why it's wrong here
Watchlists are user-defined collections of data, usually imported from CSV files, that serve as reference data for enrichment, correlation, and filtering inside analytics rules and hunting queries. They contain static values such as known malicious IPs or high-risk users, not a point-in-time record of an incident. Because a watchlist does not document a specific finding or detection, it cannot be added to an incident as evidence. Watchlists are more analogous to lookup tables than to evidence artifacts.
- ✓
Alerts
Why this is correct
Alerts are generated by built-in analytics rules, Microsoft Defender services, or custom detections and represent a single security detection with associated entities, timestamps, and severity. When an incident is created, related alerts are automatically linked, and you can explicitly add alerts from the Evidence tab to support the investigation. Each alert carries rich metadata such as rule ID, tactic, technique, and triggered logic, making it a primary evidence source. Alerts are valid evidence because they capture the exact detection that initiated or expanded the incident response.
- ✓
Bookmarks
Why this is correct
Bookmarks capture a snapshot of a specific Microsoft Sentinel hunting query result, including the query text, returned records, entity mappings, and a timestamp. This allows an analyst to preserve an exact set of search findings and later add it to an incident as evidence. Unlike a raw query, a bookmark stores the concrete result set, so it provides verifiable support for an investigation. Thus bookmarks are explicitly supported as a valid evidence source in the incident Evidence tab.
- ✗
Hunting queries
Why it's wrong here
Hunting queries are KQL statements run manually in the Microsoft Sentinel hunting area to proactively search for threats; the query itself contains only search logic, not results or time-stamped observations. Executing a query does not automatically preserve any output, and the query string cannot serve as evidence because it lacks the data that would support a conclusion. Only if an analyst explicitly creates a bookmark from the query results does the output become a bookmarked evidence artifact. Therefore, a bare hunting query is not a valid source of evidence.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.