SC-200 Respond to security incidents Practice Question
A security analyst is investigating a phishing incident in Microsoft Defender XDR. The analyst wants to see the full email content and attachments. Where should the analyst look?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The email entity page
The Email entity page in Microsoft Defender XDR provides detailed information about an email, including content and attachments. Option A is wrong because the incident timeline shows events related to the incident, not full email content. Option B is wrong because the action center is for managing response actions, not viewing email details. Option D is wrong because the user entity page shows user information, not email content.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The incident timeline
Why it's wrong here
The incident timeline shows alert chronology and related events, not raw message content. It is tempting as the default landing view for triage, but full email bodies and attachments require opening the mail entity itself from the incident's evidence or Explorer.
- ✗
The action center
Why it's wrong here
The action center lists pending automated investigation and response actions, not message bodies. It is tempting because remediation approvals live there, but full email content and attachments are viewed through the Email & collaboration entities in the incident's evidence, not the action queue.
- ✓
The email entity page
Why this is correct
The email entity page in Microsoft Defender XDR aggregates the full message body, headers, attachments and related alerts for a specific email, giving the analyst the complete content needed for phishing triage. It is reached from the incident graph or Explorer, unlike the summary views that only show metadata.
- ✗
The user entity page
Why it's wrong here
The user entity page shows identity, devices, alerts and incidents for an account, but not the raw email body or attachments. It is tempting because it aggregates everything about the recipient, and would be correct when pivoting from an email indicator to investigate the user's overall risk and activity.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.