Courseiva

SC-200 Respond to security incidents Practice Question

A security analyst is investigating a phishing incident in Microsoft Defender XDR. The analyst wants to see the full email content and attachments. Where should the analyst look?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The email entity page

The Email entity page in Microsoft Defender XDR provides detailed information about an email, including content and attachments. Option A is wrong because the incident timeline shows events related to the incident, not full email content. Option B is wrong because the action center is for managing response actions, not viewing email details. Option D is wrong because the user entity page shows user information, not email content.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The incident timeline

    Why it's wrong here

    The incident timeline shows alert chronology and related events, not raw message content. It is tempting as the default landing view for triage, but full email bodies and attachments require opening the mail entity itself from the incident's evidence or Explorer.

  • ✗

    The action center

    Why it's wrong here

    The action center lists pending automated investigation and response actions, not message bodies. It is tempting because remediation approvals live there, but full email content and attachments are viewed through the Email & collaboration entities in the incident's evidence, not the action queue.

  • ✓

    The email entity page

    Why this is correct

    The email entity page in Microsoft Defender XDR aggregates the full message body, headers, attachments and related alerts for a specific email, giving the analyst the complete content needed for phishing triage. It is reached from the incident graph or Explorer, unlike the summary views that only show metadata.

  • ✗

    The user entity page

    Why it's wrong here

    The user entity page shows identity, devices, alerts and incidents for an account, but not the raw email body or attachments. It is tempting because it aggregates everything about the recipient, and would be correct when pivoting from an email indicator to investigate the user's overall risk and activity.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.