SC-200 - Respond to Security Incidents (37% of the exam) - Section 2.5

Investigate Microsoft Defender for Endpoint device timelines, evidence, and entities.

Use the device timeline in Microsoft Defender for Endpoint to reconstruct the sequence of events on a compromised device, and examine evidence and entity pages to assess file, process, and network indicators. Review alerts and incidents in the device context and check device inventory details to understand exposure and patch state.

device timelinesevidence and entity investigationalerts and incidents in Microsoft Defender for Endpointdevice inventory

Practice question for this objective

Free sampleRespond to Security Incidentsmedium

An analyst is investigating a single onboarded Windows endpoint in Microsoft Defender for Endpoint after an alert fired at 14:07. They need a chronological view of the events recorded on that one device, such as process creations, file writes, registry changes, and network connections around the alert time, so they can reconstruct exactly what happened on it. Which feature on the device page should the analyst open to see this ordered sequence of events for that device?

  • AThe Security recommendations tab, which lists the configuration and posture weaknesses found on that device so the analyst can see the events that occurred on it leading up to the alert.
  • BThe device timeline, which presents a chronological, filterable list of the events observed on that specific device, including process, file, registry, and network activity around the time the alert was raised. Correct
  • CThe Discovered vulnerabilities tab, which enumerates the CVEs affecting software on that device so the analyst can review the sequence of activity recorded around the alert.
  • DThe Software inventory tab, which shows the applications installed on that device so the analyst can trace the chronological events that ran on it before and after the alert.
Use the device timeline in Microsoft Defender for Endpoint to view a chronological, filterable list of process, file, registry, and network events for a single device. The device timeline is the device-page feature built specifically for reconstructing activity on one endpoint. It records observed events such as process creation, file modification, registry changes, and network connections, presents them in time order, and lets the analyst filter and pivot around the moment an alert fired. The other tabs are posture and inventory views from threat and vulnerability management and contain no time-ordered runtime events.

Why A is wrong: Security recommendations surface vulnerability and configuration posture for the device through threat and vulnerability management, but they describe weaknesses to remediate, not the time-ordered runtime events the analyst needs to reconstruct the activity.

Why B is correct: The device timeline is the device-scoped chronological event view in Microsoft Defender for Endpoint, listing observed process, file, registry, and network events in time order so the analyst can reconstruct activity on that single endpoint around the alert.

Why C is wrong: Discovered vulnerabilities lists known CVEs in the device's installed software, which is useful for patching priorities but does not show any runtime process, file, or network events, so it cannot reconstruct what happened on the device.

Why D is wrong: Software inventory enumerates installed applications and versions for the device, which helps assess exposure, but it is a static list with no event timing, so it cannot provide the ordered sequence of activity the analyst requires.

See more SC-200 practice questions, answers explained.

Exam traps in Respond to Security Incidents

Answers that look right on this material and are not. Each one is a distractor from a different question in the SC-200 bank for this domain.

  • Switching the timeline Data type filter to techniques so the view shows only the MITRE ATT&CK techniques mapped to events.

    Why it is wrong: Tempting because it narrows the timeline, but it surfaces the platform's technique annotations, not the specific individual events the analyst hand-selected for the report.

  • The Timeline tab, which presents the chronological stream of process, file, registry, and network events recorded on the device.

    Why it is wrong: Tempting because the timeline is the main device-investigation surface, but it shows raw events in time order, not the filterable list of associated alerts with their severity and status.

  • Open the device entity page for each affected host so the analyst can review the alerts and timeline on those devices and infer which actions the compromised account performed.

    Why it is wrong: Device entity pages give a deep view per host and are useful for endpoint context, which makes them tempting, but they are organised around devices; reconstructing one account's full cross-domain blast radius would require manually visiting every host.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.