Courseiva

SC-200 Respond to security incidents Practice Question

Your organization uses Microsoft Sentinel. A new incident is created from a fusion alert that combines multiple low-severity alerts. The analyst needs to determine the entities involved. What should the analyst review?

⚠ Common exam trap

Many exam-takers confuse the incident's timeline (which shows events) with the entities tab (which shows the involved objects), or they mistakenly think the analytics rule's configuration reveals the actual entities, when in fact entities are dynamically extracted from alert data.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The incident's entities tab.

The incident's entities tab in Microsoft Sentinel provides a consolidated view of all entities (such as users, hosts, IP addresses, and processes) that were identified by the fusion alert. Since fusion alerts combine multiple low-severity alerts, the entities tab is the direct place to see the aggregated entities involved in the incident, enabling the analyst to understand the scope and pivot for investigation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The Sentinel Overview workbook.

    Why it's wrong here

    The Sentinel Overview workbook provides at-a-glance workspace health, ingestion status, and high-level threat detection metrics aggregated for the entire environment, not per-incident detail. It is intended for SOC managers to monitor overall trends and operational posture, but it does not list the specific accounts, hosts, IPs, or other entities associated with a single incident. Therefore, it cannot show all related entities for the incident being investigated.

  • ✓

    The incident's entities tab.

    Why this is correct

    In Microsoft Sentinel, the incident's Entities tab displays the normalized entity objects—such as user accounts, hostnames, IP addresses, URLs, and file hashes—that were extracted and mapped during incident creation. These entities are directly linked to the incident and enriched with context for pivoting, allowing analysts to see and investigate all related resources from a single, authoritative view. This is the correct place to find all related entities for the incident.

  • ✗

    The analytics rule that generated the incident.

    Why it's wrong here

    The analytics rule that generated the incident contains the detection query, scheduling, and entity mappings but only defines the logic that triggered the alert. It does not store the concrete entity values (for example, a specific malicious IP or compromised account) that were present in this particular incident; those values are extracted at runtime and captured as incident entities. Examining the rule therefore shows configuration details rather than the actual related entities of the incident in question.

  • ✗

    The incident's timeline.

    Why it's wrong here

    The incident's timeline presents a chronological sequence of alerts, activities, and events tied to the incident, letting analysts reconstruct the attack sequence and response actions over time. Although timeline events may reference entity values in their details, the timeline's purpose is to show what happened and when, not to provide a normalized, comprehensive list of all entity objects related to the incident. Entity aggregates reside separately on the Entities tab, so the timeline is not the correct source for all related entities.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.