SC-200 Respond to security incidents Practice Question
A security analyst in your company uses Microsoft Defender XDR to investigate an incident involving a user who received a malicious email. The analyst needs to block the sender's email address across all tenants in the organization. What is the most efficient way to achieve this?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
In the Microsoft 365 Defender portal, use the action center to block the sender's email address across all tenants.
Microsoft Defender XDR allows you to take action on entities like email senders. Using the action center, you can block the sender's email address globally, which applies to all tenants. Option C is correct. Option A is wrong because Exchange admin center works per tenant and is not as efficient for cross-tenant blocking. Option B is wrong because Microsoft Entra ID admin center manages identities, not email blocking. Option D is wrong because Microsoft Purview is for compliance, not email threat protection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
In the Microsoft 365 Defender portal, use the action center to block the sender's email address across all tenants.
Why this is correct
The Microsoft 365 Defender action center aggregates manual and automated remediation actions across Defender for Office 365 and other workloads, and in multi-tenant environments it allows a global operation such as blocking a sender’s email address to be applied to all affected tenants simultaneously. This action is enforced at the transport layer, ensuring malicious mail is intercepted before delivery. It is the designed workspace for centralized threat containment, unlike per-tenant management portals.
- ✗
From the Microsoft 365 Defender portal, go to Email & collaboration > Exchange admin center and block the sender.
Why it's wrong here
The Exchange admin center (EAC) is a per-tenant management interface for a single Exchange Online organization; blocking a sender there only impacts the tenant to which the administrator is currently connected. Although Exchange Online Protection supports blocked sender lists and mail flow rules, those are scoped to that specific tenant and require duplicate configuration across every tenant. The path “Email & collaboration > Exchange admin center” is a link to an external portal, not a cross-tenant Defender action center capability.
- ✗
In Microsoft Purview, create a data loss prevention policy to block the sender.
Why it's wrong here
Data loss prevention (DLP) policies in Microsoft Purview are built to detect and protect sensitive information based on data classification, restricting sharing or applying encryption when certain data types appear. DLP operates on content inspection rules, not on mail transport-level sender identity, so it cannot deny all messages from a specific external email address. Additionally, DLP policies are scoped to one tenant and are not designed to block phishing or spam senders across a multi-tenant environment.
- ✗
In Microsoft Entra ID admin center, create a conditional access policy to block the sender.
Why it's wrong here
Conditional Access in Microsoft Entra ID evaluates signals during user authentication to govern access to applications and resources; it does not inspect messaging metadata or mail flow after authentication. It also cannot apply to external senders who are attempting to deliver email, because those senders never authenticate to your tenant’s conditional access policies. Blocking a sender is a transport-level action performed by Exchange Online Protection or Defender for Office 365, making Conditional Access technically incapable of achieving this requirement.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.