Using the Evidence and Response tab to see all entities affected by a Defender XDR incident

Respond to alerts and incidents in Microsoft Defender XDR
Answer Correct answer: C — The Evidence and Response tab consolidates all entities (devices, users, files, IPs) affected by the incident.

You have a Microsoft 365 subscription that uses Microsoft Defender XDR. You need to identify all the entities affected by an incident. Which tab should you use in the Microsoft Defender portal?

  1. Investigations
  2. Assets
  3. Evidence and Response Correct Answer
  4. Alerts

Community Votes

C
65%
B
19%
D
16%

65% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The Evidence and Response tab is the consolidated view of all evidence and impacted entities for an incident, whereas Alerts lists the triggering alerts and Assets is a separate inventory view.

To identify all entities affected by a Microsoft Defender XDR incident, use the Evidence and Response tab, which aggregates every related entity (devices, users, files, IPs, mailboxes) and the response actions taken.

Choosing the Alerts or Assets tab — Alerts shows the individual alerts that fired, and Assets is a general inventory; neither presents the complete set of incident-affected entities the way Evidence and Response does.

Community Discussion (15 comments)

user636 👍 6 Selected: C
Evidence and Response: This tab provides detailed information about "all" the evidence related to an incident.
Optimizor_IT 👍 1 Selected: C
Displays a complete list (e.g., devices, users, files, IPs, mailboxes) tied to the incident’s alerts and evidence.
Onimole 👍 2 Selected: B
assets. i use it every timeeeeeeeeeeee
HAjouz 👍 3 Selected: C
However, the "Evidence and Response" tab, specifically within an incident's context, provides that deeper dive into the affected entities.
Itsmebigal 👍 2 Selected: B
I would say Alerts -> Assets tab which would show you something like this Devices (10) Users (0) Mailboxes (0) Apps (1) Cloud Resources (0)
sapphire 👍 2 Selected: C
I work with MS Defender XDR and all entities are in Evidence and Response. Correct answer.
rebecchu0731 👍 1
I asked Copilot and answer is Assets
VeiN 👍 1
Same as Q31 Topic 1
talosDevbot 👍 1 Selected: D
I'll go with D) Alerts Important part of the question is identifying all the entities AFFECTED by an incident. The Assets and Evidence & Response tabs show entities that are part of or related to the incident, not necessarily affected. Alerts tab will show you "events of the alert, which other triggered alerts caused the current alert, and all the affected entities and activities involved in the attack, including devices, files, users, and mailboxes". The table in the Alerts tab also has a column for Impacted entities
Another_one 👍 2 Selected: B
Correct me if I wrong, but should answer be B. Assets ? https://learn.microsoft.com/en-us/defender-xdr/investigate-incidents#alerts Easily view and manage all your assets in one place with the new Assets tab. This unified view includes Devices, Users, Mailboxes and Apps. The Assets tab displays the total number of assets beside its name. A list of different categories with the number of assets within that category is presented when selecting the Assets tab. All assets affected at one place.
g_man_rap 👍 4 Selected: C
Evidence and Response: This tab provides detailed information about all the evidence related to an incident. This includes the entities (such as files, devices, users, IP addresses, etc.) that are involved or impacted by the incident. The tab allows you to see how these entities are related to the threat and what actions have been taken or need to be taken. This is the most appropriate place to view all affected entities within an incident.
Studytime2023 👍 3 Selected: D
This proves it's D https://learn.microsoft.com/en-us/defender-xdr/investigate-incidents#alerts
scfitzp 👍 2
I vote D, the key here being "identify ALL the entities" https://learn.microsoft.com/en-us/defender-xdr/investigate-incidents Alerts On the Alerts tab, you can view the alert queue for alerts related to the incident and other information about them such as: Severity. The entities that were involved in the alert. The source of the alerts (Microsoft Defender for Identity, Microsoft Defender for Endpoint, Microsoft Defender for Office 365, Defender for Cloud Apps, and the app governance add-on). The reason they were linked together.
90158a0 👍 4 Selected: C
Evidence and Response: This tab provides a detailed view of all the evidence collected during the investigation, including affected entities such as files, processes, users, and devices. It also shows the response actions taken for the incident.
Hawklx 👍 1 Selected: D
Alert is better to identifying all the entities affected by an incident

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Within a Microsoft Defender XDR incident, the Evidence and Response tab provides a detailed view of all the evidence collected during the investigation, including the affected entities such as files, processes, users, devices, IP addresses, and mailboxes, along with the response actions taken or pending.

Why the Other Options Are Wrong

The Alerts tab (D) lists the individual alerts that contributed to the incident but does not consolidate all affected entities. The Assets tab (B) is a general inventory of devices, users, mailboxes, and apps, not the incident-specific affected-entity list. Investigations (A) shows automated investigation graphs, not the full entity inventory.

Community Comment Notes

user636 (6 likes), g_man_rap, and sapphire all confirm C, describing Evidence and Response as the tab that shows 'all the evidence related to an incident' including affected entities. Some commenters argue Assets or Alerts, but the documented incident-investigation experience places affected entities under Evidence and Response.

Official Reference

Related Analysis

Practice All SC-200 Questions

Access 80 questions with complete answers and detailed explanations.

View Full SC-200 Practice Test →

← Back to SC-200 Study Guide