SC-200 Manage a security operations environment Practice Question
You are a security operations analyst. You need to review all incidents from the past 24 hours that have a high severity and involve multiple users. In Microsoft Sentinel, which blade should you use?
⚠ Common exam trap
The trap here is that candidates might confuse the Hunting blade (used for proactive searches) with incident review, or think that Workbooks or Analytics can be used to filter incidents, when in fact only the Incidents blade provides the direct filtering and management interface for security incidents.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Incidents
The Incidents blade in Microsoft Sentinel is the correct place to review all security incidents, including filtering by severity and the number of users involved. It provides a centralized view where you can apply filters for 'High' severity and 'Multiple users' to meet the requirement of reviewing incidents from the past 24 hours. The Hunting, Workbooks, and Analytics blades serve different purposes and do not offer the same incident review and filtering capabilities.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Incidents
Why this is correct
The Incidents blade in Microsoft Sentinel is the dedicated operational workspace for security analysts to triage, investigate, and manage security incidents. It aggregates related alerts into a single incident, provides filtering by status, severity, and product, and supports actions like assignment and closing. This is the correct place to review existing incidents as it centralizes all detection results requiring attention.
- ✗
Hunting
Why it's wrong here
Hunting is a proactive, hypothesis-driven process where analysts run custom KQL queries across large datasets to identify potential threats that did not trigger existing analytics rules. It is not designed for reviewing incidents that have already been generated; rather, it complements the incident management flow by uncovering new, unassociated malicious activity. Navigating to Hunting to review existing incidents would be inefficient and miss the structured incident lifecycle.
- ✗
Workbooks
Why it's wrong here
Workbooks in Microsoft Sentinel are interactive dashboards that visualize data from multiple sources, enabling reporting, monitoring, and trend analysis. They are read-only views that present aggregated metrics and patterns but do not provide the necessary controls for incident triage, assignment, or status updates. While a workbook might summarize incident data, it is not the interface to directly review or act on individual incidents.
- ✗
Analytics
Why it's wrong here
The Analytics blade is where security analysts create and manage analytics rules, which define the detection logic that generates alerts and incidents. It is a configuration environment for designing scheduled queries, anomaly detection, and fusion rules, not an operational queue for reviewing existing incidents. Reviewing incidents here would confuse rule management with the day-to-day response workflow, which belongs in the Incidents blade.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.