SC-200 Respond to security incidents Practice Question
A Microsoft Defender XDR incident shows a malicious email delivered to a user, and the analyst confirms the message contains a credential-harvesting link. Before the user clicks, you need to remove the message from all mailboxes in the tenant and block the sender and URL for the future. Which Microsoft Defender for Office 365 capability should you use from the incident?
⚠ Common exam trap
It's easy for candidates to confuse investigation tooling, such as Threat Explorer, with remediation actions that actually remove and block content.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The email entity page action to soft delete, hard delete, or move to junk, plus submitting the sender and URL for blocking.
When a malicious email is confirmed, Microsoft Defender for Office 365 provides email entity remediation actions that purge the message tenant-wide and let you block the associated sender and URL. This combines cleanup of the delivered threat with prevention of recurrence. Tools that only investigate, or controls that only affect future mail, leave the delivered message reachable and do not satisfy both halves of the requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Threat Explorer with a message trace filter to identify and delete matching messages.
Why it's wrong here
Threat Explorer is a hunting and investigation tool for querying email events; it does not itself remove messages from mailboxes. Using it to find matching messages is useful for scoping, but deletion and future blocking require a remediation action. Relying on Explorer alone leaves the malicious message in place, so the user could still click the link before manual cleanup occurs.
- ✓
The email entity page action to soft delete, hard delete, or move to junk, plus submitting the sender and URL for blocking.
Why this is correct
Microsoft Defender for Office 365 exposes email entity actions in the incident that include soft delete, hard delete, and move to junk, letting you purge the message across all mailboxes. Submitting the sender and URL through the same workflow lets the service add them to tenant-level block entries. This directly removes the active threat and prevents recurrence, matching both requirements in the scenario.
- ✗
Automated investigation and response with the soft delete action on the email entity.
Why it's wrong here
Automated investigation and response can recommend or apply remediation for email, but the scenario requires an immediate, analyst-driven purge plus sender and URL blocking. Soft delete keeps the message recoverable by users, which does not satisfy removal from all mailboxes. It also does not, by itself, add the sender or URL to tenant block lists, so future messages would still be delivered.
- ✗
A mail flow transport rule in the Exchange admin center that rejects messages from the sender domain.
Why it's wrong here
A transport rule can block future mail from a sender or domain, but it does not remove the already-delivered message from user mailboxes. It also requires manual rule construction and careful scoping to avoid blocking legitimate mail. The scenario needs immediate removal of the existing message as the priority, with blocking as a secondary step, so a mail flow rule alone is incomplete.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.