mediumMultiple Choice
SC-200 Uses Microsoft 365 Defender Practice Question
An organization uses Microsoft 365 Defender. A security analyst is reviewing an incident that involves a user who clicked a phishing link in an email. The analyst wants to see the email's full timeline, including delivery, click, and any follow-up actions. Which section of the email entity page provides this information?
⚠ Common exam trap
Watch out — candidates often confuse the Investigation graph (which shows entity relationships) with the Email timeline (which shows chronological events), leading them to select the graph option when they need a sequential log of actions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Email timeline
The Email timeline section on the email entity page in Microsoft 365 Defender provides a chronological view of the email's lifecycle, including delivery, user clicks on the phishing link, and subsequent remediation actions such as soft delete or quarantine. This directly meets the analyst's need to see the full sequence of events for the incident.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Detection details
Why it's wrong here
Detection details in Microsoft Defender for Office 365 summarize the verdict, threat name, detection technology (e.g., machine learning, detonation, file reputation), and spam/phishing confidence levels for the email. However, this page provides a static snapshot of the classification result, not a time-ordered list of lifecycle events, so it cannot show when an email was delivered, when a link was clicked, or when any subsequent policy action occurred. While helpful for understanding why a message was flagged, it lacks the chronological sequence needed to reconstruct the full attack path.
- ✓
Email timeline
Why this is correct
The Email timeline in the Microsoft 365 Defender email entity page is the only view that arranges every associated action into a strict chronological order, including message intake, delivery and deferral events, URL detonation results, user click attempts, reported states, and admin remediation steps. This layout lets an analyst trace exactly when each event occurred relative to others, proving whether an email arrived before a click or whether a block was applied after delivery. It is specifically designed to answer 'what happened, and in what order,' making it the correct choice for viewing the full sequence of events for a single email.
- ✗
Threat types
Why it's wrong here
Threat types (or the threat type facets in Threat Explorer) classify an email by category such as phishing, malware, spam, or high-confidence phishing, along with the associated detection tags. These classifications are assigned at detection time and reflect the nature of the threat, but they do not include timestamps, delivery status, user interactions, or policy actions. Because they are static labels rather than a time-ordered ledger, Threat types cannot depict the lifecycle of an email or the sequence of user and system responses, so they cannot satisfy the requirement for a full event sequence.
- ✗
Investigation graph
Why it's wrong here
The Investigation graph is a relationship-based visualization that maps entities like accounts, mailboxes, IP addresses, and observed actions as nodes and edges to show how they connect during an automated investigation. It is designed to correlate multiple alerts and behaviors across an attack incident, not to produce a linear timeline of a single email's events, and its layout is driven by entity relationships rather than chronological order. While it may include events from the email, it aggregates and connects them across time and adjacent entities, so it does not provide the clean, email-centric chronological view the question asks for.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.