Courseiva

SC-200 Respond to security incidents Practice Question

You are investigating an incident in Microsoft Defender XDR. The incident involves multiple alerts from different workloads. You need to view all related alerts in a single timeline. What should you use?

⚠ Common exam trap

Test-takers frequently confuse the Incident page's unified alert timeline with Advanced hunting, thinking they need to write a KQL query to see related alerts, when in fact the Incident page automatically provides that consolidated view without any querying.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Incident page

The Incident page in Microsoft Defender XDR aggregates all alerts from different workloads (e.g., Microsoft Defender for Endpoint, Office 365, Identity) into a single, unified timeline view. This allows you to see the sequence of events and alerts related to the incident in chronological order, which is essential for understanding the attack chain and coordinating response actions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Incident page

    Why this is correct

    The incident page is the central investigation surface in Microsoft Defender XDR. It automatically aggregates all alerts related to a single attack campaign from across the Microsoft 365 security stack—Defender for Endpoint, Defender for Office 365, Defender for Identity, and Defender for Cloud Apps—into a unified view. Along with alerts, it surfaces the full attack story, affected assets, and evidence, making it the correct place to investigate the full scope of an incident. This page directly answers the need to see all related alerts in one place.

  • ✗

    Advanced hunting

    Why it's wrong here

    Advanced hunting is a powerful tool for proactive threat hunting and custom investigation using Kusto Query Language (KQL) against raw event data spanning endpoints, identities, email, and cloud apps. However, it does not automatically correlate or group alerts into an incident or show the incident-specific alert collection. To use it effectively, you must already know what queries to run and what to search for, so it is not the appropriate page for simply viewing all related alerts of a given incident during an investigation.

  • ✗

    Action center

    Why it's wrong here

    The Action center in Microsoft Defender XDR is focused on response and remediation activities, not alert correlation. It lists pending and completed mitigation actions—such as isolating a device, stopping and quarantining a file, or disabling a user account—taken across the environment. It does not show the alerts associated with an incident or the broader attack story, so it cannot satisfy the requirement to 'see all related alerts' for an incident.

  • ✗

    Device timeline

    Why it's wrong here

    The device timeline provides a detailed chronological view of events, processes, and activities that occurred on a single endpoint. It is scoped to one device, making it ideal for deep-diving into a specific machine's behavior but useless for seeing all related alerts across an entire incident that may involve many devices and workloads. Since the incident page already aggregates alerts from all impacted assets, the device timeline only offers a narrow per-device perspective and cannot provide the comprehensive incident-level alert view.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.