Courseiva

SC-200 Respond to security incidents Practice Question

An analyst is investigating a potential data exfiltration incident involving a user who accessed sensitive files from a personal device. The analyst wants to gather evidence about the device's compliance status and recent activity. Which Microsoft Intune feature should the analyst use?

⚠ Common exam trap

Candidates often confuse Azure Activity Log (which covers Azure resource operations) with Intune's device management logs, or mistakenly think Exchange message trace can reveal device compliance status.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Intune device inventory and compliance reports

Microsoft Intune device inventory and compliance reports provide detailed information about a device's compliance status, including whether it meets security policies, has required updates, and is managed correctly. This is essential for investigating potential data exfiltration from a personal device, as it allows the analyst to verify if the device was compliant and review recent activity logs within Intune.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Exchange Online message trace

    Why it's wrong here

    Exchange Online message trace is a transport audit tool that follows email messages through the Exchange Online pipeline, revealing delivery status, spam verdicts, and routing delays. It does not provide any endpoint inventory, compliance posture, or device enrollment information, so it cannot reveal whether a specific device is managed or compliant. Even if an attacker used email to steal data, message trace does not tie that email to a device's compliance state, making it irrelevant here.

  • ✓

    Microsoft Intune device inventory and compliance reports

    Why this is correct

    Microsoft Intune device inventory and compliance reports give a centralized view of every enrolled device, including its operation system, ownership type, enrollment date, and compliance status against assigned policies. These reports also surface recent device activity, such as check-ins and policy evaluation results, which allows an analyst to pinpoint non-compliant or unmanaged devices that might be involved in data exfiltration. This is the correct tool because it directly supports identifying which devices lack the required security controls.

  • ✗

    Azure Activity Log

    Why it's wrong here

    The Azure Activity Log records control-plane events for Azure resources, such as virtual machine creation, configuration changes, and role assignments, but it does not capture device-level data for Intune-managed endpoints. It has no visibility into device compliance, installed applications, or the actions a user performs locally on a device, so it cannot help determine if a device is compliant. This log is scoped to resource management, not endpoint security posture or data theft behavior.

  • ✗

    Microsoft 365 Defender's service health dashboard

    Why it's wrong here

    The Microsoft 365 Defender service health dashboard is designed to communicate availability and performance of Microsoft online services, including incidents, advisories, and historical uptime for services like Exchange Online or SharePoint. It does not expose per-device inventory, compliance status, or user activities, and it definitely cannot indicate whether a single endpoint was used for data exfiltration. Its purpose is service health communication, not endpoint security investigation data.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.