exam questions

Exam SC-200 All Questions

View all questions & answers for the SC-200 exam

Exam SC-200 topic 6 question 18 discussion

Actual exam question from Microsoft's SC-200
Question #: 18
Topic #: 6
[All SC-200 Questions]

You have a Microsoft 365 subscription that uses Microsoft Defender XDR.

You need to identify all the entities affected by an incident.

Which tab should you use in the Microsoft Defender portal?

  • A. Investigations
  • B. Assets
  • C. Evidence and Response
  • D. Alerts
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
user636
Highly Voted 9 months, 2 weeks ago
Selected Answer: C
Evidence and Response: This tab provides detailed information about "all" the evidence related to an incident.
upvoted 6 times
...
Another_one
Highly Voted 8 months, 1 week ago
Selected Answer: B
Correct me if I wrong, but should answer be B. Assets ? https://learn.microsoft.com/en-us/defender-xdr/investigate-incidents#alerts Easily view and manage all your assets in one place with the new Assets tab. This unified view includes Devices, Users, Mailboxes and Apps. The Assets tab displays the total number of assets beside its name. A list of different categories with the number of assets within that category is presented when selecting the Assets tab. All assets affected at one place.
upvoted 5 times
Krayzr
1 week, 5 days ago
Its asking for "ENTITIES" not "asstes" https://learn.microsoft.com/en-us/defender-xdr/investigate-incidents#evidence-and-response
upvoted 1 times
...
Krayzr
1 week, 5 days ago
https://learn.microsoft.com/en-us/defender-xdr/investigate-incidents#assets
upvoted 1 times
...
...
OneplusOne
Most Recent 2 weeks ago
Selected Answer: B
The Impacted Assets column in the Incidents list gives a clear overview of affected entities, and the Assets pane breaks this down further, showing items like devices and user accounts involved in an incident. Meanwhile, the Entities tab under Evidence and Response focuses more on technical artifacts such as files, processes, and services, but it doesn’t include all impacted assets like user accounts. This distinction is crucial when investigating incidents, as security teams need both perspectives—technical details from the Entities tab and broader context from the Assets pane.
upvoted 1 times
...
Adel614
1 month, 3 weeks ago
Selected Answer: C
C. Evidence and Response Considering that affected entities could include unmanaged ones by "Assets" like IP addresses, the correct tab to use in the Microsoft Defender portal to identify all entities affected by an incident would likely be Evidence and Response (C). This tab provides broader insight into the evidence collected during the investigation, which includes both managed and unmanaged entities, such as IP addresses, files, or processes.
upvoted 1 times
...
Optimizor_IT
2 months ago
Selected Answer: C
Displays a complete list (e.g., devices, users, files, IPs, mailboxes) tied to the incident’s alerts and evidence.
upvoted 1 times
...
Onimole
2 months, 3 weeks ago
Selected Answer: B
assets. i use it every timeeeeeeeeeeee
upvoted 2 times
...
HAjouz
5 months, 3 weeks ago
Selected Answer: C
However, the "Evidence and Response" tab, specifically within an incident's context, provides that deeper dive into the affected entities.
upvoted 3 times
...
Itsmebigal
6 months, 1 week ago
Selected Answer: B
I would say Alerts -> Assets tab which would show you something like this Devices (10) Users (0) Mailboxes (0) Apps (1) Cloud Resources (0)
upvoted 3 times
Itsmebigal
6 months, 1 week ago
Kind of a crap question because you would really use both. Assets for Devices, Users, Mailbox, etc and Evidence and Response for IPs, Processes, Files, etc.
upvoted 2 times
...
...
sapphire
6 months, 4 weeks ago
Selected Answer: C
I work with MS Defender XDR and all entities are in Evidence and Response. Correct answer.
upvoted 2 times
...
rebecchu0731
7 months, 1 week ago
I asked Copilot and answer is Assets
upvoted 1 times
...
VeiN
7 months, 1 week ago
Same as Q31 Topic 1
upvoted 1 times
...
talosDevbot
8 months ago
Selected Answer: D
I'll go with D) Alerts Important part of the question is identifying all the entities AFFECTED by an incident. The Assets and Evidence & Response tabs show entities that are part of or related to the incident, not necessarily affected. Alerts tab will show you "events of the alert, which other triggered alerts caused the current alert, and all the affected entities and activities involved in the attack, including devices, files, users, and mailboxes". The table in the Alerts tab also has a column for Impacted entities
upvoted 1 times
...
g_man_rap
9 months, 3 weeks ago
Selected Answer: C
Evidence and Response: This tab provides detailed information about all the evidence related to an incident. This includes the entities (such as files, devices, users, IP addresses, etc.) that are involved or impacted by the incident. The tab allows you to see how these entities are related to the threat and what actions have been taken or need to be taken. This is the most appropriate place to view all affected entities within an incident.
upvoted 4 times
...
Studytime2023
10 months, 2 weeks ago
Selected Answer: D
This proves it's D https://learn.microsoft.com/en-us/defender-xdr/investigate-incidents#alerts
upvoted 3 times
...
scfitzp
11 months ago
I vote D, the key here being "identify ALL the entities" https://learn.microsoft.com/en-us/defender-xdr/investigate-incidents Alerts On the Alerts tab, you can view the alert queue for alerts related to the incident and other information about them such as: Severity. The entities that were involved in the alert. The source of the alerts (Microsoft Defender for Identity, Microsoft Defender for Endpoint, Microsoft Defender for Office 365, Defender for Cloud Apps, and the app governance add-on). The reason they were linked together.
upvoted 2 times
...
90158a0
11 months ago
Selected Answer: C
Evidence and Response: This tab provides a detailed view of all the evidence collected during the investigation, including affected entities such as files, processes, users, and devices. It also shows the response actions taken for the incident.
upvoted 4 times
...
Hawklx
11 months, 1 week ago
Selected Answer: D
Alert is better to identifying all the entities affected by an incident
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...