SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
During a security incident, a SOC analyst needs to investigate a compromised user account that accessed multiple cloud apps. Which Microsoft Defender XDR feature provides a unified view of the attack timeline across endpoints, identities, and cloud apps?
⚠ Common exam trap
A common mix-up: candidates confuse 'Advanced hunting' (a powerful but manual query tool) with the automated, unified incident timeline that Incident Response provides, leading them to select the wrong option when the question explicitly asks for a 'unified view'.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Incident response
Incident response in Microsoft Defender XDR aggregates alerts and activities from endpoints, identities, and cloud apps into a single incident view, providing a unified attack timeline. This allows the SOC analyst to see the full scope of the compromised user account's actions across all integrated workloads without switching between consoles.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Incident response
Why this is correct
In Microsoft security platforms, "Incident response" provides a unified view that aggregates related alerts from various security workloads, such as endpoints, identities, and cloud applications. This centralized incident queue allows SOC analysts to efficiently investigate the full scope of a security breach, understand the attack story, and coordinate remediation actions, making it the primary starting point for comprehensive incident investigation.
- ✗
Microsoft Secure Score
Why it's wrong here
Microsoft Secure Score is a measurement of an organization's security posture, providing actionable recommendations to improve defenses and reduce overall risk over time. While crucial for proactive security management and identifying areas for improvement, it does not offer the real-time alert correlation, detailed forensic data, or investigative tools necessary for a SOC analyst to actively investigate an ongoing or past security incident.
- ✗
Advanced hunting
Why it's wrong here
Advanced hunting is a powerful query-based threat hunting tool that allows security analysts to proactively search for threats and anomalies across raw data in Microsoft 365 Defender using Kusto Query Language (KQL). While invaluable for deep-dive analysis and validating hypotheses *within* an investigation, it is a query interface, not a pre-correlated incident view that aggregates related alerts into a single, actionable incident for initial triage and understanding.
- ✗
Action center
Why it's wrong here
The Action center in Microsoft 365 Defender primarily serves as a centralized location to review and approve or reject automated remediation actions triggered by security alerts or incidents. It focuses on the *execution* of security actions, such as isolating devices or blocking files, rather than providing the comprehensive investigative tools, alert correlation, or timeline views that a SOC analyst needs to understand the full context and scope of a security incident.
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Incident response
Incident response is the structured approach an organization uses to identify, contain, and recover from cybersecurity incidents like data breaches or ransomware attacks.
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
About these practice questions
This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.