SC-200 Practice Question 3786
Exam: SC-200
Domain: Respond to security incidents
Difficulty: easy
An analyst is reviewing an incident in Microsoft Sentinel. The analyst needs to add notes, document external evidence links, and record shift handover notes within the incident itself. Where is this recorded?
Answer Options
A
The "Comments" tab in the incident details panel
B
Windows Notepad saved on a local USB flash drive
C
An internal company email thread
D
The public Twitter feed of the organization
Correct Answer
A: The "Comments" tab in the incident details panel
Explanation
In the incident details panel, select the "Comments" tab to append timestamped text notes and markdown-formatted documentation.