mediumMultiple Choice
SC-200 Uses Microsoft 365 Defender Practice Question
An organization uses Microsoft 365 Defender. An automated investigation on a device has determined that a file is malicious and has been blocked. The analyst wants to verify that the file was blocked and see the action taken (e.g., block, allow). Which entity page provides this information?
⚠ Common exam trap
A common mix-up: candidates confuse the Device entity page (which shows that an investigation ran) with the File entity page (which shows the specific action taken on the file), leading them to incorrectly select the Device page.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
File entity page
The File entity page in Microsoft Defender XDR provides a centralized view of a file's reputation, detection details, and the specific actions taken (e.g., blocked, allowed, quarantined) during automated investigations. Since the analyst needs to confirm the block action on a specific malicious file, this page directly displays the investigation result and the applied remediation action.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
File entity page
Why this is correct
The File entity page in Microsoft 365 Defender is the correct pivot because it aggregates the detection status and remediation actions taken on a specific file across every device in the organization. It surfaces the SHA-256 hash, prevalence, originating entity, and a timeline of automated or manual response actions such as 'Quarantine file' or 'Block file' invoked by automated investigation. This gives the SOC a single pane of glass to confirm whether the threat was fully contained.
- ✗
Device entity page
Why it's wrong here
The Device entity page is centered on machine-level state, such as sensor health, exposure level, logged-on users, software inventory, and active alerts or incidents attributed to that device. While its timeline can include file-related events, it does not summarize the actions performed on a specific file across a fleet. Therefore it is wrong because it answers 'what happened on this box' rather than 'what happened to this file everywhere.'
- ✗
User entity page
Why it's wrong here
The User entity page focuses on identity and account-level risk, including sign-in anomalies, assigned roles, incidents and alerts involving the user, and the user's devices. It does not aggregate file-level detection or quarantine actions, because its data model pivots on the account, not on the file. This makes it the wrong choice when the investigation needs cross-device file action status.
- ✗
Email entity page
Why it's wrong here
The Email entity page is specific to message artifacts in Defender for Office 365, showing delivery status, sender and recipient details, spoof detection, and attached URLs or file names within that email. It does not represent files that exist on endpoints or the endpoint remediation actions taken on those files. Selecting it would be incorrect because the question concerns file entity actions, not a message-level threat.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.