SC-200 - Respond to Security Incidents (37% of the exam) - Section 2.3

Investigate and manage Microsoft Sentinel incidents using agentic AI, embedded Copilot for Security, and case management.

Investigate alerts and incidents in Microsoft Sentinel using agentic AI and the embedded Copilot for Security to accelerate triage and summarise findings. Use case management to group related incidents, assign ownership, create incident tasks, and track investigation progress through to resolution.

alerts and incidents in Microsoft Sentinelagentic AI investigationembedded Copilot for Securitycase managementincident tasks and ownership

Practice question for this objective

Free sampleRespond to Security Incidentshard

A lead analyst is running a complex investigation that spans a Microsoft Sentinel incident, several related alerts, and notes gathered from interviews with affected staff. They want a single record that ties together the linked incidents and alerts, supports collaboration with assigned collaborators, and tracks the investigation as a managed work item across its lifecycle in the Microsoft Defender portal. Which construct should the analyst use to consolidate and manage this investigation?

  • AA second Microsoft Sentinel incident created manually, into which the analyst copies the alerts from the original incident so that all of the related evidence is gathered under one new incident record.
  • BA bookmark saved from an advanced hunting result, which preserves the queried records the analyst found and lets them annotate the rows so the evidence is kept for later reference during the investigation.
  • CA workbook saved for the investigation, which dashboards the incident and alert data together so the team can view the linked evidence and progress of the investigation in one shared visual report.
  • DA case in unified case management, which links the related incidents and alerts into one managed record and supports assigned collaborators, status, and notes to track the investigation across its lifecycle. Correct
Use a case in unified case management to link related incidents and alerts into one collaborative, lifecycle-tracked investigation record. Case management introduces the case as a first-class record that sits above individual incidents. A case links related incidents and alerts, carries its own status and assigned collaborators, and holds notes, so a lead analyst can run and track a multi-source investigation as one managed work item across its lifecycle in the Microsoft Defender portal. A duplicate incident, a hunting bookmark, and a workbook each capture or present a slice of the evidence but none provide the consolidated, collaborative, lifecycle-managed container a case does.

Why A is wrong: Creating another incident and copying alerts duplicates data rather than consolidating it, and an incident is a single detection grouping, not a cross-incident work item with collaborators and lifecycle tracking, so it does not serve as the managed investigation record.

Why B is wrong: A bookmark stores hunting findings and notes about specific records, but it captures evidence fragments rather than linking incidents and alerts into one collaborative managed work item, so it cannot consolidate or track the whole investigation.

Why C is wrong: A workbook visualises data for shared viewing but holds no case state, assigned collaborators, or lifecycle status, so it presents the evidence rather than acting as the managed record that ties the investigation together.

Why D is correct: A case is the case-management record that aggregates linked incidents and alerts into a single managed work item with collaborators, status, and notes, which is exactly the consolidated, lifecycle-tracked investigation container the analyst needs.

See more SC-200 practice questions, answers explained.

Exam traps in Respond to Security Incidents

Answers that look right on this material and are not. Each one is a distractor from a different question in the SC-200 bank for this domain.

  • Incident comments added to the activity log, where the manager types the checklist as a message and analysts reply to the thread noting which steps they have completed during their investigation.

    Why it is wrong: Comments record free-text discussion on the activity log, but they are not discrete trackable items with a completion state, so the steps could not be individually marked done or consistently reviewed, which fails the requirement for trackable checklist items.

  • The KQL assistance capability, which converts the analyst's plain-language request into a Kusto Query Language query so they can pull the incident records and compile the briefing from the returned results themselves.

    Why it is wrong: KQL assistance translates natural language into a query for the analyst to run, which yields raw records to interpret rather than an authored, non-technical narrative, so it does not produce the stakeholder-ready summary requested.

  • A scheduled analytics rule with entity mapping configured, which correlates the alerts into the incident and presents the mapped entities so the analyst can read the activity timeline on the incident page.

    Why it is wrong: Entity mapping on an analytics rule enriches the incident with identified entities, but it only populates structured fields; it does not generate a natural-language narrative of the attack or recommend guided response steps, so it does not meet the requirement.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.