Courseiva

SC-200 Respond to security incidents Practice Question

A SOC analyst is investigating a phishing campaign that targets Microsoft 365 users. The analyst needs to collect email message headers from multiple users' mailboxes. Which Microsoft 365 Defender action should the analyst use?

⚠ Common exam trap

Watch out — candidates often confuse Threat Explorer (a dedicated email investigation tool) with Advanced Hunting (a general-purpose query tool), leading them to incorrectly choose Option B, even though Advanced Hunting does not natively display raw email headers without custom KQL parsing.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use Microsoft 365 Defender > Email & collaboration > Explorer to query email headers.

Microsoft 365 Defender's Email & collaboration > Explorer (also known as Threat Explorer) is the dedicated tool for querying email message headers across multiple user mailboxes. It allows analysts to search for specific email messages by sender, recipient, subject, or other attributes, and then view the full internet message headers (RFC 5322) for forensic analysis. This is the standard workflow for investigating phishing campaigns in Microsoft 365 Defender.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use Microsoft 365 Defender > Actions & submissions to view email headers.

    Why it's wrong here

    Actions & submissions is an admin portal for manually submitting suspicious messages, URLs, or attachments to Microsoft for analysis, not a hunting interface. It does not provide a searchable query across emails, nor does it expose the raw internet message headers needed for a phishing investigation. The correct source for header data is Threat Explorer under Email & collaboration.

  • ✗

    Use Microsoft 365 Defender > Threat hunters to search for email headers.

    Why it's wrong here

    Threat hunters is not a location within Microsoft 365 Defender; it refers to an RBAC role (such as Threat Hunter) and the associated Advanced Hunting capability, which uses Kusto Query Language to query raw tables. While Advanced Hunting can access email events, it does not directly present the full MIME headers of an email as a ready-to-view report, and the option itself is not a navigation item in the portal.

  • ✗

    Use Microsoft 365 Defender > Attack simulation training to collect headers.

    Why it's wrong here

    Attack simulation training is a phishing simulation and security-awareness tool used to send controlled fake attacks and track user responses. It only generates its own synthetic campaign data and has no visibility into real inbound email messages, so it cannot collect or display headers for an actual phishing campaign.

  • ✓

    Use Microsoft 365 Defender > Email & collaboration > Explorer to query email headers.

    Why this is correct

    Email & collaboration > Explorer (Threat Explorer) is the dedicated email investigation view that lets an analyst filter by phishing indicators (sender, subject, message ID, and more) and then select individual messages to view the full message header. It also provides an export option to save headers for offline analysis, making it the correct tool for this task.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on SC-200

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. An analyst is investigating a phishing campaign that targeted multiple users. The analyst needs to identify if any users clicked a malicious link in the email. Which Microsoft Defender for Office 365 feature should be used?

easy
  • A.Safe Attachments
  • ✓ B.Threat Explorer
  • C.Attack Simulator
  • D.Safe Links

Why B: Threat Explorer (also known as Explorer) in Microsoft Defender for Office 365 provides a real-time, interactive view of threat data, including email delivery status and user actions such as clicks on malicious links. It allows analysts to filter by 'Click action' to identify users who clicked a URL that was determined to be malicious, making it the correct tool for this investigation.

Variation 2. A security operations center (SOC) analyst is investigating an incident involving a user who received a phishing email with a malicious macro. The analyst needs to determine if any other users received the same email. Which Microsoft 365 Defender feature should the analyst use?

medium
  • A.Advanced Hunting
  • B.Alert queue filtering
  • ✓ C.Threat Explorer (Investigation)
  • D.Email entity page

Why C: Threat Explorer in Microsoft 365 Defender allows hunting for email messages by sender, subject, or other attributes. Advanced Hunting is for raw queries; Email entity page shows one email; Alert queue filters by alert not email.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.