exam questions

Exam SC-200 All Questions

View all questions & answers for the SC-200 exam

Exam SC-200 topic 3 question 89 discussion

Actual exam question from Microsoft's SC-200
Question #: 89
Topic #: 3
[All SC-200 Questions]

You have a Microsoft Sentinel workspace that uses the Microsoft 365 Defender data connector.

From Microsoft Sentinel, you investigate a Microsoft 365 incident.

You need to update the incident to include an alert generated by Microsoft Defender for Cloud Apps.

What should you use?

  • A. the entity side panel of the Timeline card in Microsoft Sentinel
  • B. the Timeline tab on the incidents page of Microsoft Sentinel
  • C. the investigation graph on the incidents page of Microsoft Sentinel
  • D. the Alerts page in the Microsoft 365 Defender portal
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
kabooze
Highly Voted 1 year, 6 months ago
Selected Answer: A
It's A based on this: https://learn.microsoft.com/en-us/azure/sentinel/relate-alerts-to-incidents#add-alerts-using-the-entity-timeline-preview other people say they get answer "b" out of this but i don't see it ....
upvoted 10 times
Tuitor01
4 months, 3 weeks ago
In Incidents under Threat Management, pick an incident => View full details In the Incident details page, choose the Entities tab in the middle section of the screen. Choose an entity, on the right flying pane, choose the timeline cart For each events in the timeline you have a plus sign at the end that allows you to add this alert to an incident. Answer is therefore indeed A
upvoted 1 times
...
...
a311
Highly Voted 1 year, 7 months ago
Selected Answer: B
Actually the correct answer is B. https://learn.microsoft.com/en-us/azure/sentinel/relate-alerts-to-incidents#add-alerts-using-the-entity-timeline-preview
upvoted 6 times
kabooze
1 year, 6 months ago
If anything, that URL shows it's answer A
upvoted 3 times
...
cris_exam
1 year, 7 months ago
Based on this article, I say B as well.
upvoted 3 times
nsss
1 year, 3 months ago
The article literally states you need to go to the entity side panel and then select a timeline card
upvoted 2 times
...
...
...
Takakage
Most Recent 5 months ago
Selected Answer: A
The entity side panel of the Microsoft Sentinel timeline card is correct. In the new incident experience of Microsoft Sentinel (currently in preview), you can use the entity timeline to add alerts. This feature allows you to view all entities for a specific incident investigation and add alerts from the side panel. Therefore, if you are using the preview feature, this option is correct. Even considering that the entity timeline feature is in preview, it is the correct choice based on the content of the SC-200 certification exam. It is also important to understand the latest features and methods, as preview features may be included in the exam. cf:https://learn.microsoft.com/en-us/azure/sentinel/relate-alerts-to-incidents#add-alerts-using-the-entity-timeline-preview
upvoted 1 times
...
Tuitor01
5 months, 1 week ago
Real life experience : Incidents blade > Select Incident > View full details in the right pane > Select Entities tab in the middle pane > Select an entity > clicl on the timeline card on the right pane > click on the plus sign on the right side of greyed shielded entities > add to exising or new incident. Not the most logical workflow, but it is what it is...
upvoted 1 times
Tuitor01
5 months, 1 week ago
Therefore Answer: A
upvoted 1 times
...
...
talosDevbot
6 months, 4 weeks ago
Selected Answer: A
Sentinel > Incidents > open full details of an incident > select an entity (this will open the entity side panel which holds details about the entity) > click on the Timeline card > there's a plus sign symbol beside the alerts not included in the incident. Clicking that plus symbol will add that alert to the incident https://learn.microsoft.com/en-us/azure/sentinel/relate-alerts-to-incidents#add-alerts-using-the-entity-timeline-preview
upvoted 2 times
...
user636
8 months ago
Selected Answer: B
What a mess. Microsoft has changed the GUI in Sentinel. In the old GUI you can access the Timeline in the incident page. Ref: https://learn.microsoft.com/en-us/azure/sentinel/investigate-cases#how-to-investigate-incidents There is no "Timeline" tab available directly in Incidents pane in the new GUI. You need to open an Incident & then navigate to Entities tab & then select an entity and in the side pane select "Timeline" tab. Ref: https://learn.microsoft.com/en-us/azure/sentinel/relate-alerts-to-incidents#add-alerts-using-the-entity-timeline-preview I'd go for the answer as B. A is anyways wrong, because there is no entity side panel of the Timeline card in Microsoft Sentinel. Rather there is the Timeline side panel of the Entities card in Microsoft Sentinel. :)
upvoted 2 times
...
g_man_rap
8 months, 2 weeks ago
Selected Answer: D
Option D: The Alerts page in the Microsoft 365 Defender portal This is where you can find and manage all alerts generated by Microsoft 365 Defender components, including Defender for Cloud Apps. From this portal, you can associate these alerts with existing incidents or create new incidents. This allows for a comprehensive view and management of security incidents across all Defender products.
upvoted 2 times
...
smanzana
9 months ago
A is correct
upvoted 1 times
...
Sekpluz
10 months, 2 weeks ago
Selected Answer: A
https://learn.microsoft.com/en-us/azure/sentinel/relate-alerts-to-incidents#add-alerts-using-the-entity-timeline-preview
upvoted 2 times
...
albatros06
1 year ago
Selected Answer: C
By using the investigation graph in Microsoft Sentinel, you can explore connections between the existing Microsoft 365 Defender data and potentially find the relevant Defender for Cloud Apps alert related to the incident you're investigating. T
upvoted 2 times
...
DChilds
1 year ago
Selected Answer: D
The wording for option A, B and C makes me doubt them as answers because 1. The Timeline card does not have an entity side panel, it's actually the entity side panel that has a Timeline card tab. 2. The timelines tab is not on the incidents page of Sentinel and 3. The investigation graph is not on the incidents page but rather on the incident details panel. The Alert page in Defender 365 portal does allow you to associate an alert with an incident, so this would be my choice. Thought on this?
upvoted 3 times
...
Ramye
1 year, 2 months ago
Selected Answer: A
Answer confirmed by items 5 & 6 listed here https://learn.microsoft.com/en-us/azure/sentinel/relate-alerts-to-incidents#add-alerts-using-the-entity-timeline-preview
upvoted 1 times
...
kostask
1 year, 2 months ago
Selected Answer: D
The question is tricky. If you read the following link you will see in limitations that you cannot link defender alerts to defender incidents from Sentinel. You can only do that from Defender portal. https://learn.microsoft.com/en-us/azure/sentinel/relate-alerts-to-incidents#add-alerts-using-the-entity-timeline-preview
upvoted 1 times
kostask
1 year, 2 months ago
Now that i thought it again, it says a link a defender for cloud app incident to a M365 Incident. and based on that you can do the following "You can add Microsoft Defender XDR alerts to non-Defender incidents, and non-Defender alerts to Defender incidents, in the Microsoft Sentinel portal." So A should be correct
upvoted 1 times
...
...
ApexPredator84
1 year, 4 months ago
In the exam on 21/12/2023
upvoted 3 times
...
Murtuza
1 year, 4 months ago
In the entity page side panel, select the Timeline card. A is the correct choice based on the links provided
upvoted 3 times
...
shadowdark83
1 year, 5 months ago
Selected Answer: A
Based on the documentation below, I think the aswer is A. https://learn.microsoft.com/en-us/azure/sentinel/relate-alerts-to-incidents#add-alerts-using-the-entity-timeline-preview
upvoted 4 times
...
danb67
1 year, 6 months ago
Selected Answer: D
Changed my mind. This question has annoyed. I use Sentinel and A, B or C as worded in the question does not allow us to link to another incident. However D does. I have alerts in Sentinel that have been ingested from Defender. If I go to the alert in Defender I can 'link to another incident
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago