SC-200 Respond to security incidents Practice Question
You are investigating an incident in Microsoft Defender XDR. The incident involves multiple alerts from different workloads. You need to view all related alerts in a single timeline. What should you use?
⚠ Common exam trap
Test-takers frequently confuse the Incident page's unified alert timeline with Advanced hunting, thinking they need to write a KQL query to see related alerts, when in fact the Incident page automatically provides that consolidated view without any querying.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Incident page
The Incident page in Microsoft Defender XDR aggregates all alerts from different workloads (e.g., Microsoft Defender for Endpoint, Office 365, Identity) into a single, unified timeline view. This allows you to see the sequence of events and alerts related to the incident in chronological order, which is essential for understanding the attack chain and coordinating response actions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Incident page
Why this is correct
The incident page is the central investigation surface in Microsoft Defender XDR. It automatically aggregates all alerts related to a single attack campaign from across the Microsoft 365 security stack—Defender for Endpoint, Defender for Office 365, Defender for Identity, and Defender for Cloud Apps—into a unified view. Along with alerts, it surfaces the full attack story, affected assets, and evidence, making it the correct place to investigate the full scope of an incident. This page directly answers the need to see all related alerts in one place.
- ✗
Advanced hunting
Why it's wrong here
Advanced hunting is a powerful tool for proactive threat hunting and custom investigation using Kusto Query Language (KQL) against raw event data spanning endpoints, identities, email, and cloud apps. However, it does not automatically correlate or group alerts into an incident or show the incident-specific alert collection. To use it effectively, you must already know what queries to run and what to search for, so it is not the appropriate page for simply viewing all related alerts of a given incident during an investigation.
- ✗
Action center
Why it's wrong here
The Action center in Microsoft Defender XDR is focused on response and remediation activities, not alert correlation. It lists pending and completed mitigation actions—such as isolating a device, stopping and quarantining a file, or disabling a user account—taken across the environment. It does not show the alerts associated with an incident or the broader attack story, so it cannot satisfy the requirement to 'see all related alerts' for an incident.
- ✗
Device timeline
Why it's wrong here
The device timeline provides a detailed chronological view of events, processes, and activities that occurred on a single endpoint. It is scoped to one device, making it ideal for deep-diving into a specific machine's behavior but useless for seeing all related alerts across an entire incident that may involve many devices and workloads. Since the incident page already aggregates alerts from all impacted assets, the device timeline only offers a narrow per-device perspective and cannot provide the comprehensive incident-level alert view.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.