SC-200 Respond to security incidents Practice Question
A SOC analyst receives a phishing alert in Microsoft Defender for Office 365. The analyst needs to quickly determine if any users clicked the malicious link. Which action should the analyst take first?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Open the email entity page to view click details
The email entity page in Microsoft Defender for Office 365 provides detailed information about a specific email, including click verdicts for any URLs contained within. This allows the analyst to quickly see if any users clicked the malicious link. Option A (Threat Explorer) can also be used, but it requires more steps to filter for the specific email and then view click details. Option B (user entity page) shows user-specific activities and alerts, but not email-specific click details. Option D (hunting query in Microsoft Sentinel) is effective but slower than directly viewing the email entity page in Defender for Office 365.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use Threat Explorer to search for the email subject
Why it's wrong here
Threat Explorer in Defender for Office 365 can locate messages by subject, sender, or recipient, and it remains a valid investigative tool for hunting across mail flows. However, it requires manually setting query filters, adjusting the date range, and then correlating the returned result back to the original alert, which adds unnecessary steps during triage. The email entity page, in contrast, is directly reachable from the alert and already scoped to the suspicious message, making it the faster and more targeted choice for a single-phishing incident.
- ✗
Open the user entity page for each recipient
Why it's wrong here
The user entity page is user-centric: it displays a recipient's account profile, roles, group memberships, sign-in activity, and sometimes mailbox-related settings, but it does not expose email-specific click behavior. Email click details, such as whether a recipient clicked a malicious URL and the resulting verdict, are captured and stored at the email-message level, not at the user level. Consequently, opening the user entity page for each recipient would require additional navigation to separate message actions and still would not directly answer whether a phishing link was clicked, making it an inefficient detour.
- ✓
Open the email entity page to view click details
Why this is correct
The email entity page is the correct destination because it consolidates the full message record from Microsoft Defender for Office 365, including delivery status, threat name, detection technology, and the recipient-specific URL click verdict. Its Click details section explicitly indicates whether each intended recipient clicked the link, whether the click was allowed or blocked, and the time of the click, which is exactly the evidence needed to assess the impact of a phishing alert. This page is purpose-built for single-message triage and provides near-instant visibility without requiring a custom query or cross-referencing multiple data sources.
- ✗
Run a hunting query in Microsoft Sentinel
Why it's wrong here
Running a hunting query in Microsoft Sentinel is a manual, custom investigation that requires writing KQL, understanding the exact schema of tables such as EmailEvents and EmailUrlInfo, and joining those records to identify recipient clicks. Sentinel may not receive mailbox or Safe Links data unless a diagnostic setting is configured for Office 365, meaning the required click details could be absent or delayed due to data ingestion latency. Even when properly configured, a hunting query reintroduces context-switching and setup time that the email entity page already avoids, so it is overkill for triaging a single existing alert.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.