MS-900 Describe Microsoft 365 apps and services Practice Question
A user in your organization receives an email from an unknown sender with a link to a fake login page. The user reports it. You need to analyze the threat and check if other users received similar emails. Which Microsoft 365 Defender feature should you use?
⚠ Common exam trap
Test-takers frequently confuse Threat Explorer (a manual hunting and analysis tool) with Automated investigation and response (AIR), which is an automated reaction system, leading them to pick D because they think 'investigation' implies manual analysis, but AIR is fully automated and not designed for ad-hoc email searches.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Threat Explorer (Explorer)
Threat Explorer (Explorer) is the correct tool because it provides a real-time, interactive view of email threats, allowing you to search for and analyze specific messages (like the phishing link) across all users. You can use filters such as sender, recipient, or URL to determine if other users received the same malicious email, enabling rapid threat hunting and response.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Threat analytics
Why it's wrong here
In Microsoft 365 Defender, Threat Analytics is a threat intelligence solution that provides curated reports about active adversaries, campaigns, and techniques with mitigation guidance. It does not offer a per-email search interface, so you cannot enter a message ID, subject, or recipient to locate a specific unknown email. This makes it the wrong choice because it gives strategic/global threat context rather than granular, email-level investigation.
- ✓
Threat Explorer (Explorer)
Why this is correct
Threat Explorer in Defender for Office 365 is a real-time investigation tool that lets security teams search and filter email records by attributes such as threat type, sender, recipient, subject, message ID, and delivery action. In this scenario, an administrator could use Explorer to locate the exact unknown email, inspect its threat verdicts, and view the mail flow or delivery action. It is the correct option because it is explicitly designed for manual, forensic analysis of email threats in a Microsoft 365 tenant.
- ✗
Attack simulation training
Why it's wrong here
Attack simulation training is a security-awareness capability in Microsoft 365 Defender that creates mock phishing and training campaigns to evaluate user susceptibility. It generates its own synthetic emails and reports on user interactions, but it does not ingest or search real email traffic from your organization. Therefore, it cannot be used to investigate an actual unknown email a user received, making it incorrect for this investigative scenario.
- ✗
Automated investigation and response (AIR)
Why it's wrong here
Automated Investigation and Response (AIR) in Microsoft 365 Defender uses predefined playbooks to automatically investigate alerts and take remediation actions such as quarantining a file, disabling a mailbox, or blocking a sender. It is triggered by signals and runs without manual ad-hoc searching, so a user cannot query for a specific unknown email using AIR. Because the task requires a manual, custom investigation, AIR is the wrong tool even though it has email-related capabilities.
Go deeper
Related to this question
Learn chapter
Microsoft Defender for Office 365
Key term
Microsoft 365
Microsoft 365 is a subscription-based cloud service from Microsoft that combines productivity tools like Office apps with security, device management, and online storage.
Key term
User
A user is any person, system, or device that interacts with an IT service, resource, or identity system, typically authenticated through credentials and authorized to perform specific actions.
About these practice questions
Courseiva writes every MS-900 question from scratch — 794 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.