easyMultiple Choice
SC-200 Practice Question: A security analyst is reviewing an email-related…
A security analyst is reviewing an email-related incident in Microsoft 365 Defender. The analyst wants to see the full delivery details, including the sender IP, authentication status, and the reason why the email was determined to be malicious. Which section of the email entity page should the analyst open?
⚠ Common exam trap
Watch out — candidates often confuse the 'Details' section (which shows basic metadata) with the 'Detection details' section (which provides the full forensic analysis), leading them to select Option B incorrectly because they assume 'Details' is the most comprehensive option.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Detection details
The Detection details section of the email entity page in Microsoft 365 Defender provides comprehensive information about why an email was determined to be malicious, including the sender IP address, authentication status (SPF, DKIM, DMARC results), and the specific detection technology or policy that triggered the verdict. This section consolidates the full delivery details and threat analysis into a single view, making it the correct choice for the analyst's needs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Detection details
Why this is correct
The Detection details tab in the Microsoft 365 Defender email entity page aggregates the detection technologies (e.g., anti-phishing, anti-spam, anti-malware) and associated threats, along with sender IP, SPF/DKIM/DMARC authentication results, and the detection source (e.g., S666, T103). This section is the authoritative source for understanding why the message was flagged, including the specific threat name and confidence level. Unlike other tabs, it provides the forensic evidence of the detection, which is essential for investigating an email incident.
- ✗
Details
Why it's wrong here
The Details tab provides general metadata such as subject, sender, recipient, email direction, and message ID, but it does not surface the detection technology or authentication results. It is useful for identifying the message context but not for determining why the system flagged it. In an incident investigation, details alone cannot confirm the detection reason.
- ✗
Timeline
Why it's wrong here
The Timeline tab shows the chronological sequence of events including email delivery, user actions (open, click, report), and remediation steps (purge, quarantine), but it does not display the detection reasoning. It helps reconstruct the incident timeline, not the detection logic. The detection details are separate from the timeline events.
- ✗
Preview
Why it's wrong here
The Preview tab renders the email body content, including attachments and links, to allow analysts to verify the message's semantic content and potential malicious indicators. It shows what the user saw, but it does not include detection metadata like authentication results or detection technology. While preview can support manual analysis, it is not the source of the system's detection rationale.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SC-200
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. During an incident investigation in Microsoft 365 Defender, an analyst examines an email that was reported as phishing. The analyst opens the email entity page and looks at the 'Detection details' section. Which piece of information would the analyst find there?
medium- A.The delivery location and whether the email was delivered to Inbox, Junk, or Quarantine.
- B.The authentication statuses (SPF, DKIM, DMARC) for the sender domain.
- C.The sender IP address and the recipient email address.
- ✓ D.The detection technology (e.g., Advanced ML, Reputation) and if the email was part of a phish simulation or a campaign.
Why D: The 'Detection details' section on the email entity page in Microsoft 365 Defender specifically shows the detection technology used (e.g., Advanced ML, Reputation, Bulk) and whether the email was part of a phishing simulation or a campaign. This information helps analysts understand how the email was identified as malicious and its context within broader threat activity.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.