SC-200 Respond to security incidents Practice Question
A SOC analyst is reviewing an incident in Microsoft Sentinel that involves a user receiving a phishing email with a malicious attachment. The attachment was opened on a device managed by Microsoft Intune. Which Microsoft Defender XDR component would have provided the earliest detection of the malicious file?
⚠ Common exam trap
Candidates often choose Microsoft Defender for Office 365 (Option B) because they focus on the phishing email vector, but the question explicitly states the attachment was already opened on the device, shifting the earliest detection point to the endpoint protection layer.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Defender for Endpoint
Microsoft Defender for Endpoint (MDE) provides the earliest detection of malicious files at the endpoint level. When the user opens the malicious attachment on an Intune-managed device, MDE's real-time protection (antivirus and behavior monitoring) scans the file immediately upon execution or write, blocking the threat before it can execute further. This is faster than cloud-based or email-level detections because the file is already on the device.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Defender for Cloud Apps
Why it's wrong here
Microsoft Defender for Cloud Apps is a cloud access security broker (CASB) that focuses on discovering and governing cloud app usage, shadow IT, and data exfiltration via sanctioned or unsanctioned cloud services. It relies on API connectors and proxies, not on an endpoint agent, so it does not inspect or detect local file execution or malware on a device. While it can ingest alerts from Defender for Endpoint for correlation, the actual malware detection and process-level telemetry originate from the endpoint solution, not from Cloud Apps.
- ✗
Microsoft Defender for Office 365
Why it's wrong here
Microsoft Defender for Office 365 protects email and collaboration workloads by scanning attachments, URLs, and phishing attempts before delivery, and it also provides post-delivery protection in Exchange Online. However, this alert is about a file detection on the device, meaning the malicious file was executed or observed locally, which falls outside the email scanning scope. Even if the file entered via email, Defender for Office 365 would not trigger a device-level malware detection on its own; that requires an endpoint security agent.
- ✓
Microsoft Defender for Endpoint
Why this is correct
Microsoft Defender for Endpoint is the correct source because it is an endpoint detection and response (EDR) solution that installs a sensor on the device, continuously monitoring processes, file executions, registry changes, and behaviors. Its real-time protection and behavioral analytics would detect the malicious file directly on the endpoint, and this detection would surface as an alert in Microsoft Sentinel. As the only option with a local agent capable of seeing file execution, it is the definitive source for this incident.
- ✗
Microsoft Purview Data Loss Prevention
Why it's wrong here
Microsoft Purview Data Loss Prevention (DLP) is designed to identify, monitor, and protect sensitive data according to compliance policies, blocking actions like copying, printing, or sharing that data outside authorized channels. It does not scan for malware signatures or behavioral patterns of malicious executables; its telemetry is focused on data classification and policy violations, not on process-level security events. Therefore, a malware detection alert in Sentinel cannot be attributed to Purview DLP, which lacks both the sensor and the detection logic for endpoint threats.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.