Courseiva

SC-200 Respond to security incidents Practice Question

A security operations center (SOC) analyst is investigating an incident involving a user who received a phishing email with a malicious macro. The analyst needs to determine if any other users received the same email. Which Microsoft 365 Defender feature should the analyst use?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Threat Explorer (Investigation)

Threat Explorer in Microsoft 365 Defender allows hunting for email messages by sender, subject, or other attributes. Advanced Hunting is for raw queries; Email entity page shows one email; Alert queue filters by alert not email.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Advanced Hunting

    Why it's wrong here

    Advanced Hunting can locate the email, but it requires writing a Kusto Query Language (KQL) query against tables such as EmailEvents and EmailAttachmentInfo. For a SOC analyst trying to quickly find all instances of a known email, this adds unnecessary complexity and risks errors from malformed queries. Threat Explorer offers the same metadata search with a no-code interface, making it more appropriate for this standard email investigation.

  • ✗

    Alert queue filtering

    Why it's wrong here

    The alert queue is designed to display security alerts generated by detection logic, not the underlying raw email records. Filtering it by email subject, sender, or message ID is not supported because alerts aggregate multiple signals and do not maintain a direct one-to-one mapping to individual mail items. The analyst must first identify the email via Threat Explorer, then pivot to any associated alerts, so the alert queue cannot be the starting point for this search.

  • ✓

    Threat Explorer (Investigation)

    Why this is correct

    Threat Explorer (Investigation) is the correct choice because it is a purpose-built email security search tool that lets the analyst search all mail across the organization using filters like sender, recipient, subject, message ID, and delivery status. It provides a comprehensive, KQL-free view of every instance of the email, including delivery actions and threat detections, and supports direct remediation. This makes it the natural first tool for locating and analyzing a specific reported email.

  • ✗

    Email entity page

    Why it's wrong here

    The email entity page opens only after a specific email has already been located and selected from a tool such as Threat Explorer or a user entity timeline. It shows detailed properties of that single email object, including sender, recipients, threat verdicts, and associated alerts, but it does not offer any search capability to find emails across the organization. Therefore, relying on it before locating the email would be ineffective; Threat Explorer must be used first to discover the email instance.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.