SC-200 Respond to security incidents Practice Question
You are a SOC analyst using Microsoft Defender XDR. An incident named 'Suspicious PowerShell download' is assigned to you. You need to quickly determine the initial entry point and the scope of affected devices. Which action should you perform first within the incident?
⚠ Common exam trap
The trap here is assuming that advanced hunting or automated investigation should be the first step, when in fact the timeline provides the quickest contextual overview.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Review the incident timeline to identify the first alert and related entities.
The incident timeline in Microsoft Defender XDR provides a chronological view of alerts and activities, allowing analysts to quickly identify the initial alert and affected entities. This is critical for understanding the entry point and scope before taking further action. Other options, while valid later, do not directly address the immediate need for triage.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Export the incident details to a CSV file for offline analysis.
Why it's wrong here
Exporting to CSV is useful for documentation but does not provide immediate interactive insights. It delays triage and lacks the contextual linking of entities. The timeline offers real-time correlation and is the recommended first step for understanding an incident.
- ✗
Initiate an automated investigation to remediate the threat.
Why it's wrong here
Automated investigation can remediate but should not be the first action before understanding the incident. Initiating it prematurely might disrupt evidence or take unnecessary actions. The analyst should first assess the incident to determine appropriate response.
- ✗
Run an advanced hunting query to list all devices with PowerShell events.
Why it's wrong here
Advanced hunting is powerful but requires crafting a query and may return excessive data. It does not immediately show the incident's entry point or scope without additional filtering. The timeline already correlates relevant events for this incident, making it a faster first step.
- ✓
Review the incident timeline to identify the first alert and related entities.
Why this is correct
The incident timeline in Microsoft Defender XDR aggregates alerts and activities chronologically, helping you pinpoint the initial alert and affected entities. This provides the entry point and scope, enabling efficient triage. Other options may be useful later but do not directly answer the immediate need.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.