Courseiva

SC-200 Respond to security incidents Practice Question

Which TWO are valid sources of evidence in a Microsoft Sentinel incident? (Choose two.)

⚠ Common exam trap

Candidates often confuse 'sources of evidence' with 'tools used during investigation'—playbooks and hunting queries are actions or workflows, not static evidence records stored within the incident.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Alerts

Alerts are a core evidence type in Microsoft Sentinel incidents because they represent the raw security findings that trigger an incident. When an alert is generated from a detection rule (e.g., analytics rule, fusion, or scheduled query), it is automatically linked to the incident as evidence, providing the initial context and supporting data for investigation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Playbooks

    Why it's wrong here

    Playbooks are cloud-based automated response workflows in Microsoft Sentinel, typically built on Azure Logic Apps. They can be invoked during incident handling to perform actions such as sending emails, creating tickets, or blocking IPs, but the workflow itself is not a data record or investigation artifact. Evidence must capture a detection, a search result, or an entity observation; a playbook's automation steps do not meet that definition. Therefore, playbooks are not considered valid sources of evidence.

  • ✗

    Watchlists

    Why it's wrong here

    Watchlists are user-defined collections of data, usually imported from CSV files, that serve as reference data for enrichment, correlation, and filtering inside analytics rules and hunting queries. They contain static values such as known malicious IPs or high-risk users, not a point-in-time record of an incident. Because a watchlist does not document a specific finding or detection, it cannot be added to an incident as evidence. Watchlists are more analogous to lookup tables than to evidence artifacts.

  • ✓

    Alerts

    Why this is correct

    Alerts are generated by built-in analytics rules, Microsoft Defender services, or custom detections and represent a single security detection with associated entities, timestamps, and severity. When an incident is created, related alerts are automatically linked, and you can explicitly add alerts from the Evidence tab to support the investigation. Each alert carries rich metadata such as rule ID, tactic, technique, and triggered logic, making it a primary evidence source. Alerts are valid evidence because they capture the exact detection that initiated or expanded the incident response.

  • ✓

    Bookmarks

    Why this is correct

    Bookmarks capture a snapshot of a specific Microsoft Sentinel hunting query result, including the query text, returned records, entity mappings, and a timestamp. This allows an analyst to preserve an exact set of search findings and later add it to an incident as evidence. Unlike a raw query, a bookmark stores the concrete result set, so it provides verifiable support for an investigation. Thus bookmarks are explicitly supported as a valid evidence source in the incident Evidence tab.

  • ✗

    Hunting queries

    Why it's wrong here

    Hunting queries are KQL statements run manually in the Microsoft Sentinel hunting area to proactively search for threats; the query itself contains only search logic, not results or time-stamped observations. Executing a query does not automatically preserve any output, and the query string cannot serve as evidence because it lacks the data that would support a conclusion. Only if an analyst explicitly creates a bookmark from the query results does the output become a bookmarked evidence artifact. Therefore, a bare hunting query is not a valid source of evidence.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.