Courseiva

MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365

A compliance administrator needs to investigate emails that may be part of a phishing campaign. Which Microsoft 365 capability is the best fit?

⚠ Common exam trap

Many candidates confuse general Microsoft 365 admin tools (like Bookings or Teams) with security-specific capabilities, failing to recognize that only Threat Explorer provides the granular email investigation features required for phishing analysis.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Threat Explorer in Microsoft Defender for Office 365

Threat Explorer in Microsoft Defender for Office 365 is the correct tool because it provides security teams with a powerful, real-time investigation interface to search, filter, and analyze email threats, including phishing campaigns. It allows administrators to view detailed email metadata, delivery actions, and threat types (e.g., phishing, malware) across the organization, making it the best fit for investigating suspected phishing emails.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Microsoft Bookings

    Why it's wrong here

    Microsoft Bookings is a scheduling and appointment management tool within Microsoft 365, designed to let customers book time with staff. It does not provide any email investigation, threat hunting, or compliance capabilities. In the context of investigating potentially malicious emails, Bookings has no access to mail flow, message trace, or threat signals, so it cannot be used for this security requirement.

  • ✗

    Microsoft Teams live events

    Why it's wrong here

    Microsoft Teams live events is a broadcast and communication feature for hosting large-scale virtual events. It is not a security or compliance investigation tool; it does not parse email headers, identify phishing campaigns, or provide insights into message delivery. Therefore, it cannot be used to investigate emails that may be malicious or non-compliant.

  • ✗

    OneDrive sync client

    Why it's wrong here

    The OneDrive sync client is a desktop application that synchronizes local files with OneDrive for Business, enabling offline access and collaboration. While it may interact with email attachments stored in the cloud, it does not provide any email inspection, threat detection, or compliance monitoring functions. It simply replicates files and cannot investigate email messages or their threats.

  • ✓

    Threat Explorer in Microsoft Defender for Office 365

    Why this is correct

    Threat Explorer is a real-time report and investigation tool in Microsoft Defender for Office 365 that allows security teams to view and analyze email threats, including malware, phishing, and spam. It provides powerful filters for delivery actions, detection technology, and campaign insights, enabling admins to identify and remediate malicious emails. This makes it the appropriate tool for a compliance administrator to investigate potentially harmful emails.

Go deeper

Related to this question

About these practice questions

Courseiva writes every MS-900 question from scratch — 794 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.