Courseiva
mediumMultiple Choice

SC-200 Practice Question: An analyst is investigating a file that was…

An analyst is investigating a file that was detected as malicious on several devices. In Microsoft 365 Defender, where can the analyst find information about the file's prevalence, global reputation, and related incidents?

⚠ Common exam trap

Microsoft often tests the distinction between entity pages by making candidates confuse the File entity page (which shows prevalence and reputation) with the Device entity page (which shows device-specific alerts but not file-level global data).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

File entity page

The File entity page in Microsoft 365 Defender aggregates file-level telemetry, including prevalence (number of devices/users), global reputation (Microsoft's cloud-based threat intelligence), and a timeline of related incidents. This page is the single pane of glass for file-centric investigations, pulling data from Microsoft Defender for Endpoint, Office 365, and other XDR sources.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    File entity page

    Why this is correct

    The file entity page is the designated central repository for file intelligence in Microsoft Defender XDR, consolidating the file name, SHA-1 and SHA-256 hashes, file size, publisher/signing information, global and organization prevalence, observed devices, and current verdict. It aggregates detonation outcomes from deep analysis, related alerts, and the complete set of machines where the file was seen, enabling an analyst to determine both maliciousness and organizational exposure in one place. This is why it is the correct starting point for investigating a detected file.

  • ✗

    Device entity page

    Why it's wrong here

    The device entity page centers on a single machine's configuration, sensor health, security posture, installed software, and device-level alert history. Although the device timeline may show file creation or execution events for that particular endpoint, it cannot provide the file's organization-wide prevalence or enrichment data such as OSINT reputation and certificate validity. For a file that may have affected many devices, the device page gives only a narrow, per-machine view rather than the aggregated file perspective needed.

  • ✗

    User entity page

    Why it's wrong here

    The user entity page in Microsoft Defender XDR is identity-centric: it surfaces a user's risk level, sign-in activity, assigned alerts, and related incidents. If the detected file was executed or accessed by a user, you might pivot from the user's timeline to the file, but this page does not aggregate the file's prevalence, hash reputation, or detonation results across devices. Therefore, it cannot serve as the central location for a file-based investigation.

  • ✗

    Email entity page

    Why it's wrong here

    The email entity page in Microsoft Defender for Office 365 focuses on a single message's metadata, such as sender, recipients, delivery status, and attached artifacts. While a malicious file may originate as an email attachment and appear on this page as a linked artifact, the page does not show how widespread the file is on endpoints or provide cross-machine verification of the file's reputation. An analyst would need to click through to the file entity page to analyze the detected payload itself.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.