Creating a Microsoft Sentinel bookmark from the Hunting page to support an incident investigation
You have a Microsoft Sentinel workspace. You are investigating an incident that involves multiple alerts, events, and entities. You need to create a bookmark for the investigation. The solution must minimize administrative effort. Which settings should you use?
Community Votes
39% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Sentinel bookmarks are produced from hunting queries on the Hunting page and can be added to a new or existing incident there, making Hunting the correct settings area rather than Incidents, Content hub, or Logs.
While investigating a multi-alert Sentinel incident, you create a bookmark with minimal effort; bookmarks are created and added to incidents from the Hunting page, which is the dedicated blade for saving query results as bookmarks.
Choosing Logs or Incidents — bookmarks originate from hunting queries on the Hunting page; the Logs blade runs queries but bookmark creation and incident association are performed from Hunting.
Community Discussion (9 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
In Microsoft Sentinel, bookmarks are created from hunting queries on the Hunting page, where you run a query, select result rows, and add them as bookmarks; you can also add bookmarks to a new or existing incident directly from Hunting. This is the lowest-effort path to capture investigation findings.Why the Other Options Are Wrong
The Logs blade (D) executes KQL but bookmark creation and incident association happen on the Hunting page, not in raw Logs. The Incidents page (A) is for managing aggregated incidents, not for creating bookmarks from query results. Content hub (C) is for deploying solutions and playbooks, unrelated to bookmarks.Community Comment Notes
sapphire (8 likes) cites https://learn.microsoft.com/en-us/azure/sentinel/bookmarks#add-bookmarks-to-a-new-or-existing-incident, confirming bookmarks are added via Hunting. HAjouz notes the Hunting selection under Threat management. Some commenters argue Logs or Incidents, but the documented bookmark workflow is Hunting-centric.Official Reference
Related Analysis
Practice All SC-200 Questions
Access 80 questions with complete answers and detailed explanations.
View Full SC-200 Practice Test →