SC-200 Respond to security incidents Practice Question
A security operations center (SOC) analyst is investigating an incident involving a user who received a phishing email with a malicious macro. The analyst needs to determine if any other users received the same email. Which Microsoft 365 Defender feature should the analyst use?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Threat Explorer (Investigation)
Threat Explorer in Microsoft 365 Defender allows hunting for email messages by sender, subject, or other attributes. Advanced Hunting is for raw queries; Email entity page shows one email; Alert queue filters by alert not email.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Advanced Hunting
Why it's wrong here
Advanced Hunting can locate the email, but it requires writing a Kusto Query Language (KQL) query against tables such as EmailEvents and EmailAttachmentInfo. For a SOC analyst trying to quickly find all instances of a known email, this adds unnecessary complexity and risks errors from malformed queries. Threat Explorer offers the same metadata search with a no-code interface, making it more appropriate for this standard email investigation.
- ✗
Alert queue filtering
Why it's wrong here
The alert queue is designed to display security alerts generated by detection logic, not the underlying raw email records. Filtering it by email subject, sender, or message ID is not supported because alerts aggregate multiple signals and do not maintain a direct one-to-one mapping to individual mail items. The analyst must first identify the email via Threat Explorer, then pivot to any associated alerts, so the alert queue cannot be the starting point for this search.
- ✓
Threat Explorer (Investigation)
Why this is correct
Threat Explorer (Investigation) is the correct choice because it is a purpose-built email security search tool that lets the analyst search all mail across the organization using filters like sender, recipient, subject, message ID, and delivery status. It provides a comprehensive, KQL-free view of every instance of the email, including delivery actions and threat detections, and supports direct remediation. This makes it the natural first tool for locating and analyzing a specific reported email.
- ✗
Email entity page
Why it's wrong here
The email entity page opens only after a specific email has already been located and selected from a tool such as Threat Explorer or a user entity timeline. It shows detailed properties of that single email object, including sender, recipients, threat verdicts, and associated alerts, but it does not offer any search capability to find emails across the organization. Therefore, relying on it before locating the email would be ineffective; Threat Explorer must be used first to discover the email instance.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.