SC-200 · Question #368
You have a Microsoft 365 E5 subscription that uses Microsoft Defender XDR. You are investigating an incident. You need to review the incident tasks that were performed. What can you use on the…
The correct answer is D. Tasks, Activity log, and Alert timeline. The Microsoft Defender XDR Incident page provides all three features to support investigation workflows. The Tasks tab lets analysts create, assign, and track investigation tasks associated with the incident. The Activity log records all actions taken on the incident…
Question
You have a Microsoft 365 E5 subscription that uses Microsoft Defender XDR. You are investigating an incident. You need to review the incident tasks that were performed. What can you use on the Incident page?
Options
- ATasks only
- BTasks and Activity log only
- CTasks and Alert timeline only
- DTasks, Activity log, and Alert timeline
How the community answered
(39 responses)- A3% (1)
- B8% (3)
- C18% (7)
- D72% (28)
Explanation
The Microsoft Defender XDR Incident page provides all three features to support investigation workflows. The Tasks tab lets analysts create, assign, and track investigation tasks associated with the incident. The Activity log records all actions taken on the incident - including comments, status changes, assignments, and automated actions - providing a full audit trail. The Alert timeline presents the chronological sequence of alerts that comprise the incident, helping analysts understand the attack progression. All three are accessible directly from the Incident page, making D the correct and complete answer.
Community Discussion
No community discussion yet for this question.