SC-200 Practice Question 3786

Exam: SC-200
Domain: Respond to security incidents
Difficulty: easy
An analyst is reviewing an incident in Microsoft Sentinel. The analyst needs to add notes, document external evidence links, and record shift handover notes within the incident itself. Where is this recorded?

Answer Options

A
The "Comments" tab in the incident details panel
B
Windows Notepad saved on a local USB flash drive
C
An internal company email thread
D
The public Twitter feed of the organization

Correct Answer

A: The "Comments" tab in the incident details panel

Explanation

In the incident details panel, select the "Comments" tab to append timestamped text notes and markdown-formatted documentation.