SC-200 Respond to security incidents Practice Question
Your organization uses Microsoft Sentinel. You receive an incident for a potential malware outbreak. You need to quickly see which entities are involved (e.g., IPs, hosts, accounts). Where should you look?
⚠ Common exam trap
It's easy for candidates to confuse the Alerts tab (which shows raw alert details) with the Entities tab (which provides a consolidated, entity-focused view), leading them to select the Alerts tab when they need to quickly see all involved IPs, hosts, and accounts.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Entities tab
The Entities tab in a Microsoft Sentinel incident provides a consolidated view of all related entities such as IP addresses, hosts, user accounts, and other resources that were identified during the alert investigation. This allows you to quickly assess the scope of a potential malware outbreak by seeing which systems and identities are involved, without needing to navigate through raw alerts or timeline events.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Incident timeline
Why it's wrong here
The incident timeline provides a chronological view of the activities, alert triggers, and status changes that occurred during the incident lifecycle. It is designed to help you reconstruct the sequence of events, not to expose a consolidated list of the involved accounts, hosts, or IP addresses. While timeline entries may mention an entity when an action occurred, this view does not aggregate or index all entities for quick reference, so it would not satisfy the requirement to view all associated entities.
- ✗
Comments section
Why it's wrong here
The comments section is a free-form collaboration space where analysts can capture notes, hypotheses, and communication history about the incident. It does not automatically extract or display any structured entity data from the alert content. You could manually type entity names into a comment, but that would be unreliable and incomplete compared to the built-in Entities tab, making this the wrong location for comprehensively identifying all entities.
- ✓
Entities tab
Why this is correct
The Entities tab on the incident page aggregates and displays every entity that Microsoft Sentinel extracted from the alert data, such as user accounts, hostnames, IP addresses, URLs, and file hashes. Each entity is presented with its type, name, and a link to its full investigation details, allowing you to pivot directly to related incidents and actions. This dedicated, structured view is the appropriate place to identify all entities associated with the incident.
- ✗
Alerts tab
Why it's wrong here
The Alerts tab lists the individual alerts that have been grouped into this incident, showing alert titles, severity, and status. Although those alerts contain raw event data that can include entity identifiers, the tab itself does not render a unified entity inventory; it merely shows which alerts fired. To see the extracted and normalized entities, you need to use the Entities tab rather than scanning through each alert's raw details.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.