StudyToCert

All certifications / SC-200 / Lessons

Microsoft Certified: Security Operations Analyst Associate SC-200 · Domain 2: Respond to security incidents

Defender portal incident queue: triage, assignment, attack story, alert correlation, linking alerts and merging incidents, classification and determination

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

An alert is a single detection. An incident is a collection of related alerts and the evidence behind them that together tell the story of one attack. Defender XDR (extended detection and response) automatically correlates alerts from endpoint, identity, email, cloud apps and, with Sentinel onboarded, security information and event management (SIEM) sources into incidents, based on shared entities such as the same user, device, file or IP address, and on timing. Working at the incident level saves time and shows the whole attack instead of fragments, which is why the security operations center (SOC) queue is built around incidents rather than alerts.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 6 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study SC-200 for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the SC-200 study plan