SC-200 Respond to security incidents Practice Question
You are a SOC analyst using Microsoft Defender XDR. An incident named "Multi-stage intrusion on FIN-PC01" contains alerts for a malicious PowerShell script, a suspicious outbound connection to a known C2 IP, and credential dumping activity. You need to perform an investigation that automatically shows the full attack story, including related entities, alerts, and timeline, without manually correlating each alert. What should you use?
⚠ Common exam trap
The trap here is assuming that advanced hunting or Sentinel's investigation graph provides the same automated incident correlation as the Defender XDR attack story timeline.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The incident's attack story timeline in the Microsoft Defender XDR portal
The attack story timeline in Microsoft Defender XDR is designed to automatically correlate all alerts, entities, and events from an incident into a single, interactive timeline. It eliminates manual correlation and provides a comprehensive view of the attack, which is exactly what the analyst needs to understand the full scope quickly.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The Microsoft Sentinel incident investigation graph
Why it's wrong here
Microsoft Sentinel's investigation graph is used within Sentinel, not Microsoft Defender XDR. While it can show entity relationships, it is not the native incident attack story in Defender XDR and would require separate data ingestion and configuration. The scenario specifically involves Defender XDR incidents, so this is not the correct tool.
- ✓
The incident's attack story timeline in the Microsoft Defender XDR portal
Why this is correct
The attack story timeline automatically aggregates all alerts, entities, and events related to the incident into a single visual timeline. It shows the full chain of events, including process execution, network connections, and user actions, enabling rapid correlation without manual effort. This is the primary investigation view for incidents in Microsoft Defender XDR.
- ✗
Automated investigation and response (AIR) investigation details page
Why it's wrong here
AIR provides automated remediation actions and investigation results, but it does not present the full attack story timeline with all related alerts and entities in a single view. AIR is focused on automated response, not on the manual investigation timeline that shows the complete attack chain.
- ✗
Advanced hunting with a custom KQL query across DeviceProcessEvents and DeviceNetworkEvents
Why it's wrong here
Advanced hunting allows custom queries but requires you to manually write KQL, correlate results, and interpret the data. It does not automatically produce a unified attack story or timeline for the incident. While powerful, it is not the automated investigation view that consolidates alerts and entities for you.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.