Courseiva

SC-200 Manage a security operations environment Practice Question

You are configuring a Microsoft Sentinel workbook to display incident metrics. You want to show the average time to triage incidents over the last 30 days. Which data source should you use?

⚠ Common exam trap

It's easy for candidates to confuse the SecurityAlert table (which holds raw alert data) with the SecurityIncident table (which holds the correlated incident record), leading them to incorrectly choose SecurityAlert for incident-level metrics.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SecurityIncident table.

The SecurityIncident table in Microsoft Sentinel contains all incident-related data, including timestamps for creation, triage, and resolution. To calculate the average time to triage (e.g., the time between incident creation and the first triage action), you query this table using KQL to compute the mean duration. The other tables (CommonSecurityLog, SecurityAlert, SigninLogs) do not store incident lifecycle metadata.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    CommonSecurityLog table.

    Why it's wrong here

    CommonSecurityLog is a normalized table for syslog/CEF messages ingested from on-premises security appliances such as Palo Alto, Fortinet, or Cisco ASA. It contains transport and device-specific fields like DeviceVendor, DeviceProduct, and raw event payload, but it has no concept of incident lifecycle or triage state. While these logs can generate alerts that ultimately feed incidents, the table itself holds individual log events, not the aggregated incident records needed to display creation and triage times in a workbook.

  • ✓

    SecurityIncident table.

    Why this is correct

    SecurityIncident is the canonical Microsoft Sentinel table for incident records, generated by the incident management service. Each row represents a single incident and includes authoritative fields such as IncidentNumber, Title, Status, Owner, CreatedTimeUTC, FirstActivityTimeUTC, LastActivityTimeUTC, and TriageTimeUTC. Querying this table directly lets a workbook aggregate incidents by time or status without joins or approximations, making it the correct source for incident lifecycle metrics like created and triaged times.

  • ✗

    SecurityAlert table.

    Why it's wrong here

    SecurityAlert stores individual detections produced by analytics rules, with fields such as AlertName, AlertSeverity, StartTimeUtc, EndTimeUtc, and entities. Microsoft Sentinel groups one or more alerts into an incident, so a single incident can correspond to multiple SecurityAlert rows, causing over-counting if used in an incident-focused workbook. Additionally, SecurityAlert lacks incident-scoped fields like IncidentNumber and TriageTime, so it cannot report on incident creation or triage behavior directly.

  • ✗

    SigninLogs table.

    Why it's wrong here

    SigninLogs is an Microsoft Entra ID table that captures authentication activity, including fields like UserPrincipalName, AppDisplayName, SignInErrorCode, and ConditionalAccessStatus. It is an identity event stream, not a security incident repository, and contains no references to Sentinel incidents, alert grouping, or triage times. A workbook using SigninLogs could illustrate sign-in failures or risk, but it is fundamentally misaligned with the task of displaying incident creation and triage timelines.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.