Using the Evidence and Response tab to see all entities affected by a Defender XDR incident
You have a Microsoft 365 subscription that uses Microsoft Defender XDR. You need to identify all the entities affected by an incident. Which tab should you use in the Microsoft Defender portal?
Community Votes
65% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The Evidence and Response tab is the consolidated view of all evidence and impacted entities for an incident, whereas Alerts lists the triggering alerts and Assets is a separate inventory view.
To identify all entities affected by a Microsoft Defender XDR incident, use the Evidence and Response tab, which aggregates every related entity (devices, users, files, IPs, mailboxes) and the response actions taken.
Choosing the Alerts or Assets tab — Alerts shows the individual alerts that fired, and Assets is a general inventory; neither presents the complete set of incident-affected entities the way Evidence and Response does.
Community Discussion (15 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Within a Microsoft Defender XDR incident, the Evidence and Response tab provides a detailed view of all the evidence collected during the investigation, including the affected entities such as files, processes, users, devices, IP addresses, and mailboxes, along with the response actions taken or pending.Why the Other Options Are Wrong
The Alerts tab (D) lists the individual alerts that contributed to the incident but does not consolidate all affected entities. The Assets tab (B) is a general inventory of devices, users, mailboxes, and apps, not the incident-specific affected-entity list. Investigations (A) shows automated investigation graphs, not the full entity inventory.Community Comment Notes
user636 (6 likes), g_man_rap, and sapphire all confirm C, describing Evidence and Response as the tab that shows 'all the evidence related to an incident' including affected entities. Some commenters argue Assets or Alerts, but the documented incident-investigation experience places affected entities under Evidence and Response.Official Reference
Related Analysis
Practice All SC-200 Questions
Access 80 questions with complete answers and detailed explanations.
View Full SC-200 Practice Test →