SC-200 Manage a security operations environment Practice Question
You are a SOC analyst using Microsoft Sentinel. You receive an incident with high severity. You need to quickly gather additional context about the affected user account, including recent sign-in logs and role assignments. Which feature should you use?
⚠ Common exam trap
Watch out — candidates often confuse the investigative, entity-focused nature of Entity pages with the broader, dashboard-oriented purpose of Workbooks, leading them to choose Option A because both involve visual data presentation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Entity pages
Entity pages in Microsoft Sentinel provide a centralized, pre-built view of a specific entity (such as a user account), aggregating related alerts, incidents, and data from connected sources like Microsoft Entra ID sign-in logs and role assignments. This allows a SOC analyst to quickly gather contextual information without manually querying multiple data sources, making it the ideal feature for high-severity incidents requiring rapid investigation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Sentinel Workbooks
Why it's wrong here
Sentinel Workbooks are interactive dashboards that visualize multiple KQL queries across a workspace, giving a high-level security posture view with charts and KPIs. They can incorporate entity-specific data, but they do not provide a pre-built, entity-centric timeline or automatically collate related alerts and incidents for a single user or host. For immediate context on a specific entity, you need the entity page’s interactive pivot interface, not an aggregated dashboard.
- ✗
Analytics rules
Why it's wrong here
Analytics rules (scheduled or near-real-time) are the detection engine of Sentinel, defining the conditions that generate alerts and incidents based on query frequency and lookback periods. While reviewing an alert, these rules have already done their work; they do not offer a navigable history of a given entity’s prior alerts, user behavior changes, or relationship to other resources. They are not an investigation surface, but the source configuration for the alert you are currently triaging.
- ✓
Entity pages
Why this is correct
Entity pages in Sentinel are the correct investigation surface because they aggregate everything known about a specific entity (user, host, IP, mailbox, etc.) into a single timeline, including related alerts, incidents, bookmarks, and anomalies. They leverage UEBA to present risk scores, behavioral insights, and peer anomaly comparisons, which are essential for understanding whether the entity is compromised or merely active. This entity-centric view directly supports the 'entity timeline' requirement that other tools lack.
- ✗
Hunting queries
Why it's wrong here
Hunting queries are proactive, exploratory KQL queries—often mapped to the MITRE ATT&CK framework—that analysts run to find suspicious activity that hasn’t yet triggered alerts. They operate on data ranges and return result sets, but they do not construct a dynamic, entity-centered timeline of an alert that has already fired, nor do they automatically link related incidents, bookmarks, and UEBA insights for a single entity. Hunting is for finding unknown threats, not for drilling into the context of a known alert.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.