SC-200 Respond to security incidents Practice Question
After a security incident, you need to preserve evidence from a compromised Microsoft 365 tenant. What is the best method to preserve data?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Place the user's mailbox and OneDrive on litigation hold
Placing the user's mailbox and OneDrive on litigation hold is the best method for preserving evidence because it preserves all data in its original state, preventing deletion or modification. Option A (backup of entire tenant) is excessive and not immediate. Option B (eDiscovery) is for search and export, not preservation. Option C (export to PST and delete) destroys the original evidence, which is inadvisable.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Take a backup of the entire tenant
Why it's wrong here
A full tenant backup captures service configuration and mailbox content for recovery, not forensic evidence. It cannot guarantee bit-level integrity, chain of custody, or capture volatile artefacts such as audit logs and deleted items. Backup is the right choice for disaster recovery or ransomware restoration, where restoring service continuity matters rather than admissible proof.
- ✗
Use Microsoft Purview eDiscovery to search and export
Why it's wrong here
eDiscovery search and export retrieves content but does not itself place custodial holds, so items can be modified or purged before collection completes. It is the right tool for identifying and exporting responsive material once preservation is already in place.
- ✗
Export the data to a PST file and delete the original
Why it's wrong here
Exporting to PST then deleting the originals destroys the source evidence and breaks chain of custody, making the copy inadmissible. PST export is intended for migrating or archiving mailbox data, not for preserving incident evidence.
- ✓
Place the user's mailbox and OneDrive on litigation hold
Why this is correct
Placing the mailbox and OneDrive on litigation hold preserves all existing and future content immutably, preventing deletion or alteration during investigation, which satisfies the evidence-preservation requirement. This retention mechanism operates independently of the user, unlike simple export or backup copies.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.