Creating a Microsoft Sentinel bookmark from the Hunting page to support an incident investigation

Detect threats by using the Microsoft Sentinel platform
Answer Correct answer: B — Sentinel bookmarks are created and added to incidents from the Hunting page, the lowest-effort path.

You have a Microsoft Sentinel workspace. You are investigating an incident that involves multiple alerts, events, and entities. You need to create a bookmark for the investigation. The solution must minimize administrative effort. Which settings should you use?

  1. Incidents
  2. Hunting Correct Answer
  3. Content hub
  4. Logs

Community Votes

B
39%
D
30%
A
30%

39% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Sentinel bookmarks are produced from hunting queries on the Hunting page and can be added to a new or existing incident there, making Hunting the correct settings area rather than Incidents, Content hub, or Logs.

While investigating a multi-alert Sentinel incident, you create a bookmark with minimal effort; bookmarks are created and added to incidents from the Hunting page, which is the dedicated blade for saving query results as bookmarks.

Choosing Logs or Incidents — bookmarks originate from hunting queries on the Hunting page; the Logs blade runs queries but bookmark creation and incident association are performed from Hunting.

Community Discussion (9 comments)

sapphire 👍 8 Selected: B
Hunting is correct answer. https://learn.microsoft.com/en-us/azure/sentinel/bookmarks#add-bookmarks-to-a-new-or-existing-incident
jamspurple 👍 2 Selected: D
To CREATE a bookmark you go to Threat Management > Hunting, when you run a hunting query you need to go to the LOGS pane to create the bookmark. So the answer is Logs. If you want to add bookmarks to a new or existing incident, this is done through the Hunting pane. But the question specifically asks how you create a bookmark. Full explanation here including screenshots of the Logs pane being used. https://learn.microsoft.com/en-us/azure/sentinel/bookmarks#add-a-bookmark
HAjouz 👍 1 Selected: B
To Create a bookmark -> For Microsoft Sentinel in the Azure portal, under Threat management select Hunting.
siheom 👍 2 Selected: A
should be A
CDR 👍 3 Selected: D
Bookmarks are exclusively created and managed within the Logs section. Here's a summary to solidify this: Incidents: The Incidents section is for managing and investigating security incidents. It provides a consolidated view of alerts, entities, and related information. You can't create bookmarks here. Hunting: The Hunting section is for proactively searching for threats using hunting queries. While you might discover interesting data during a hunting exercise, you still need to go to the Logs section to create a bookmark for the corresponding KQL query. Logs: The Logs section (powered by Log Analytics) is where you write and run KQL queries against your security data. This is the only place where you can create and manage bookmarks.
firdaous9 👍 2 Selected: A
Use Hunting for proactive threat detection. Use Incidents for investigating and managing evidence for pre-aggregated alerts and related events.
Krankenwagen 👍 3 Selected: A
I would prefer A. Not B, because Hunting is more appropriate for pro-active searching for anomalies Inside the incident, go to the Investigate tab. "As you investigate the various alerts, events, and entities related to the incident, you can bookmark the key items that are important for your investigation."
Itsmebigal 👍 2 Selected: D
Per Azure What is it? Hunting bookmarks enable users to save, tag, annotate, share and investigate results from a Log Analytics query. How does it work? Select a hunting query from the Microsoft Sentinel hunting page and click "View query results" in hunting query details to view the results in Log Analytics. Use the check boxes to select one or more rows that contain the information you find interesting and click "Add bookmark". This preserves the data in the row for future reference.
chirva 👍 3
GPT4: Here’s why Hunting is the appropriate setting: Hunting: This is where you can run queries to proactively search for threats in your environment. When you find something suspicious or noteworthy during your hunting activities, you can create a bookmark to save the specific event or finding for further investigation or correlation with other data.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

In Microsoft Sentinel, bookmarks are created from hunting queries on the Hunting page, where you run a query, select result rows, and add them as bookmarks; you can also add bookmarks to a new or existing incident directly from Hunting. This is the lowest-effort path to capture investigation findings.

Why the Other Options Are Wrong

The Logs blade (D) executes KQL but bookmark creation and incident association happen on the Hunting page, not in raw Logs. The Incidents page (A) is for managing aggregated incidents, not for creating bookmarks from query results. Content hub (C) is for deploying solutions and playbooks, unrelated to bookmarks.

Community Comment Notes

sapphire (8 likes) cites https://learn.microsoft.com/en-us/azure/sentinel/bookmarks#add-bookmarks-to-a-new-or-existing-incident, confirming bookmarks are added via Hunting. HAjouz notes the Hunting selection under Threat management. Some commenters argue Logs or Incidents, but the documented bookmark workflow is Hunting-centric.

Official Reference

Related Analysis

Practice All SC-200 Questions

Access 80 questions with complete answers and detailed explanations.

View Full SC-200 Practice Test →

← Back to SC-200 Study Guide