Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Unlimited Access

Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.

Exam SC-200 topic 3 question 89 discussion

Actual exam question from Microsoft's SC-200
Question #: 89
Topic #: 3
[All SC-200 Questions]

You have a Microsoft Sentinel workspace that uses the Microsoft 365 Defender data connector.

From Microsoft Sentinel, you investigate a Microsoft 365 incident.

You need to update the incident to include an alert generated by Microsoft Defender for Cloud Apps.

What should you use?

  • A. the entity side panel of the Timeline card in Microsoft Sentinel
  • B. the Timeline tab on the incidents page of Microsoft Sentinel
  • C. the investigation graph on the incidents page of Microsoft Sentinel
  • D. the Alerts page in the Microsoft 365 Defender portal
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
a311
Highly Voted 7 months, 3 weeks ago
Selected Answer: B
Actually the correct answer is B. https://learn.microsoft.com/en-us/azure/sentinel/relate-alerts-to-incidents#add-alerts-using-the-entity-timeline-preview
upvoted 6 times
kabooze
6 months, 2 weeks ago
If anything, that URL shows it's answer A
upvoted 2 times
...
cris_exam
7 months, 3 weeks ago
Based on this article, I say B as well.
upvoted 3 times
nsss
3 months, 3 weeks ago
The article literally states you need to go to the entity side panel and then select a timeline card
upvoted 1 times
...
...
...
kabooze
Highly Voted 6 months, 2 weeks ago
Selected Answer: A
It's A based on this: https://learn.microsoft.com/en-us/azure/sentinel/relate-alerts-to-incidents#add-alerts-using-the-entity-timeline-preview other people say they get answer "b" out of this but i don't see it ....
upvoted 6 times
...
albatros06
Most Recent 2 weeks, 3 days ago
Selected Answer: C
By using the investigation graph in Microsoft Sentinel, you can explore connections between the existing Microsoft 365 Defender data and potentially find the relevant Defender for Cloud Apps alert related to the incident you're investigating. T
upvoted 1 times
...
DChilds
1 month, 2 weeks ago
Selected Answer: D
The wording for option A, B and C makes me doubt them as answers because 1. The Timeline card does not have an entity side panel, it's actually the entity side panel that has a Timeline card tab. 2. The timelines tab is not on the incidents page of Sentinel and 3. The investigation graph is not on the incidents page but rather on the incident details panel. The Alert page in Defender 365 portal does allow you to associate an alert with an incident, so this would be my choice. Thought on this?
upvoted 2 times
...
Ramye
2 months, 3 weeks ago
Selected Answer: A
Answer confirmed by items 5 & 6 listed here https://learn.microsoft.com/en-us/azure/sentinel/relate-alerts-to-incidents#add-alerts-using-the-entity-timeline-preview
upvoted 1 times
...
kostask
3 months ago
Selected Answer: D
The question is tricky. If you read the following link you will see in limitations that you cannot link defender alerts to defender incidents from Sentinel. You can only do that from Defender portal. https://learn.microsoft.com/en-us/azure/sentinel/relate-alerts-to-incidents#add-alerts-using-the-entity-timeline-preview
upvoted 1 times
kostask
3 months ago
Now that i thought it again, it says a link a defender for cloud app incident to a M365 Incident. and based on that you can do the following "You can add Microsoft Defender XDR alerts to non-Defender incidents, and non-Defender alerts to Defender incidents, in the Microsoft Sentinel portal." So A should be correct
upvoted 1 times
...
...
ApexPredator84
4 months, 3 weeks ago
In the exam on 21/12/2023
upvoted 3 times
...
Murtuza
5 months, 1 week ago
In the entity page side panel, select the Timeline card. A is the correct choice based on the links provided
upvoted 3 times
...
shadowdark83
6 months, 2 weeks ago
Selected Answer: A
Based on the documentation below, I think the aswer is A. https://learn.microsoft.com/en-us/azure/sentinel/relate-alerts-to-incidents#add-alerts-using-the-entity-timeline-preview
upvoted 4 times
...
danb67
6 months, 3 weeks ago
Selected Answer: D
Changed my mind. This question has annoyed. I use Sentinel and A, B or C as worded in the question does not allow us to link to another incident. However D does. I have alerts in Sentinel that have been ingested from Defender. If I go to the alert in Defender I can 'link to another incident
upvoted 1 times
...
danb67
6 months, 3 weeks ago
B based on https://learn.microsoft.com/en-us/azure/sentinel/relate-alerts-to-incidents#add-alerts-using-the-entity-timeline-preview
upvoted 1 times
danb67
6 months, 3 weeks ago
Changed my mind to A as the wording in B is strange and doesn't fit
upvoted 2 times
...
...
IT_Nerd31
7 months ago
The provided answer is correct. The article provided by a311 does illustrate how to do this, however, I believe that the instructions were misinterpreted. . Launch Sentinel . Go to incidents . Click on incident >> Investigate . In the middle pane you have the Overview tab and the Entities tab, click on Entities . Select one of the entities, and notice the blade that appears The options on this screen are, Info, Timeline, Insight. If you select timeline, you will see other alerts that you can add to the incident. B says the incident timeline, which are the alerts that are added to the incident. Now read A one more time: the entity side panel of the Timeline card in Microsoft Sentinel
upvoted 5 times
...
donathon
8 months ago
D for me too
upvoted 1 times
...
mali1969
8 months, 1 week ago
Selected Answer: D
D. the Alerts page in the Microsoft 365 Defender portal. Open the Microsoft 365 Defender portal and select Alerts. Find the alert that you want to add to the incident and select it. In the alert details page, select Add to existing incident. In the Add alert to incident pane, select the incident that you want to update and then select Add. This will add the alert to the incident in both Microsoft 365 Defender and Microsoft Sentinel portals. Any changes you make to the incident in Microsoft 365 Defender will be synchronized to the same incident in Microsoft Sentinel
upvoted 2 times
...
Fez786
8 months, 1 week ago
This new question arrived today 9th september 2023. Can someone please verify the correct answer?
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...