Courseiva
mediumMultiple Choice

SC-200 Practice Question: A phishing email was delivered to several users

A phishing email was delivered to several users. The analyst wants to find all messages in the campaign, see delivery actions, and perform remediation from the Microsoft 365 Defender portal. Which tool should they use?

⚠ Common exam trap

It's easy for candidates to confuse Threat Explorer with the general-purpose Activity log or Secure Score, assuming any security-related tool can handle email threats, but only Threat Explorer is designed for deep email threat hunting and remediation within Microsoft 365 Defender.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Threat Explorer.

Threat Explorer (also known as Explorer) in Microsoft 365 Defender is the correct tool because it provides a comprehensive view of email threats, including phishing campaigns. It allows analysts to search for all messages in a campaign, review delivery actions (e.g., blocked, delivered to junk, or delivered), and perform remediation actions such as soft delete, hard delete, or move to quarantine directly from the portal.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Threat Explorer.

    Why this is correct

    Threat Explorer is the primary hunting and investigation console in Microsoft Defender for Office 365 Plan 2, providing near-real-time and historical email records, message delivery status, and threat metadata. It allows an analyst to filter by sender, recipient, message ID, or detection technology to identify which users received a specific phishing message and then perform remediation actions such as soft-deleting the emails or purging malicious URLs. This makes it the correct tool for tracing and remediating an individual phishing campaign.

  • ✗

    Microsoft Secure Score.

    Why it's wrong here

    Microsoft Secure Score is a posture-management dashboard that assigns points for adopting security controls and completing improvement actions across Microsoft 365, Azure, and other workloads. It does not ingest mail-flow records or per-message threat signals, so it cannot show which inboxes received a phishing email or provide any campaign-level investigation evidence. While a Secure Score can indicate whether anti-phishing policies are enabled, it lacks the operational telemetry needed to investigate a specific delivered message.

  • ✗

    Azure Activity log.

    Why it's wrong here

    The Azure Activity log records subscription-level control-plane events such as resource deployments, VM state changes, and role assignments, with no visibility into Exchange Online mail flow or message transport. Email delivery decisions, threat blocks, and user mailbox interactions are not captured in Azure Activity; they reside in Exchange Online message trace and Defender for Office 365 data sources. Using this log to investigate a phishing email would yield no evidence about the campaign and would misidentify the correct telemetry source.

  • ✗

    Microsoft Defender Vulnerability Management software inventory.

    Why it's wrong here

    Microsoft Defender Vulnerability Management's software inventory is an endpoint-focused dataset that enumerates installed applications, versions, and known CVEs on managed devices. It contains no email transport, message delivery, or mailbox-level phishing indicators, and it cannot correlate a malicious email with user actions or storage. While the dashboard can reveal missing patches that might be exploited later, it cannot trace or remediate email threats, making it irrelevant for this investigation.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.