nerdexam
Microsoft

SC-200 · Question #368

You have a Microsoft 365 E5 subscription that uses Microsoft Defender XDR. You are investigating an incident. You need to review the incident tasks that were performed. What can you use on the…

The correct answer is D. Tasks, Activity log, and Alert timeline. The Microsoft Defender XDR Incident page provides all three features to support investigation workflows. The Tasks tab lets analysts create, assign, and track investigation tasks associated with the incident. The Activity log records all actions taken on the incident…

Submitted by the_admin· Apr 18, 2026

Question

You have a Microsoft 365 E5 subscription that uses Microsoft Defender XDR. You are investigating an incident. You need to review the incident tasks that were performed. What can you use on the Incident page?

Options

  • ATasks only
  • BTasks and Activity log only
  • CTasks and Alert timeline only
  • DTasks, Activity log, and Alert timeline

How the community answered

(39 responses)
  • A
    3% (1)
  • B
    8% (3)
  • C
    18% (7)
  • D
    72% (28)

Explanation

The Microsoft Defender XDR Incident page provides all three features to support investigation workflows. The Tasks tab lets analysts create, assign, and track investigation tasks associated with the incident. The Activity log records all actions taken on the incident - including comments, status changes, assignments, and automated actions - providing a full audit trail. The Alert timeline presents the chronological sequence of alerts that comprise the incident, helping analysts understand the attack progression. All three are accessible directly from the Incident page, making D the correct and complete answer.

Community Discussion

No community discussion yet for this question.

Full SC-200 Practice