SC-200 Respond to security incidents Practice Question
An analyst is investigating a potential data exfiltration incident involving a user who accessed sensitive files from a personal device. The analyst wants to gather evidence about the device's compliance status and recent activity. Which Microsoft Intune feature should the analyst use?
⚠ Common exam trap
Candidates often confuse Azure Activity Log (which covers Azure resource operations) with Intune's device management logs, or mistakenly think Exchange message trace can reveal device compliance status.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Intune device inventory and compliance reports
Microsoft Intune device inventory and compliance reports provide detailed information about a device's compliance status, including whether it meets security policies, has required updates, and is managed correctly. This is essential for investigating potential data exfiltration from a personal device, as it allows the analyst to verify if the device was compliant and review recent activity logs within Intune.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Exchange Online message trace
Why it's wrong here
Exchange Online message trace is a transport audit tool that follows email messages through the Exchange Online pipeline, revealing delivery status, spam verdicts, and routing delays. It does not provide any endpoint inventory, compliance posture, or device enrollment information, so it cannot reveal whether a specific device is managed or compliant. Even if an attacker used email to steal data, message trace does not tie that email to a device's compliance state, making it irrelevant here.
- ✓
Microsoft Intune device inventory and compliance reports
Why this is correct
Microsoft Intune device inventory and compliance reports give a centralized view of every enrolled device, including its operation system, ownership type, enrollment date, and compliance status against assigned policies. These reports also surface recent device activity, such as check-ins and policy evaluation results, which allows an analyst to pinpoint non-compliant or unmanaged devices that might be involved in data exfiltration. This is the correct tool because it directly supports identifying which devices lack the required security controls.
- ✗
Azure Activity Log
Why it's wrong here
The Azure Activity Log records control-plane events for Azure resources, such as virtual machine creation, configuration changes, and role assignments, but it does not capture device-level data for Intune-managed endpoints. It has no visibility into device compliance, installed applications, or the actions a user performs locally on a device, so it cannot help determine if a device is compliant. This log is scoped to resource management, not endpoint security posture or data theft behavior.
- ✗
Microsoft 365 Defender's service health dashboard
Why it's wrong here
The Microsoft 365 Defender service health dashboard is designed to communicate availability and performance of Microsoft online services, including incidents, advisories, and historical uptime for services like Exchange Online or SharePoint. It does not expose per-device inventory, compliance status, or user activities, and it definitely cannot indicate whether a single endpoint was used for data exfiltration. Its purpose is service health communication, not endpoint security investigation data.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.