SC-200 Content Search Practice Question
During a security incident, you need to collect email messages associated with a phishing campaign from multiple mailboxes in Microsoft 365. Which tool should you use to search and export these emails?
⚠ Common exam trap
The trap is confusing alert-triage tools (Defender XDR, incident investigation) with content-search tools — candidates must map 'search and export mailbox content' to Purview Content Search, not to Defender.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Content Search in the Microsoft Purview compliance portal.
Content Search in the Microsoft Purview compliance portal is the purpose-built tool for searching across Exchange mailboxes (and SharePoint/OneDrive) and exporting results to a PST or mailbox. It supports keyword queries, date ranges, sender/recipient filters, and bulk export across multiple mailboxes, which matches the phishing-campaign scenario.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Advanced Hunting in Microsoft Defender XDR.
Why it's wrong here
Advanced Hunting queries telemetry through KQL but returns tabular event records, not exportable mailbox items, so it cannot collect the actual messages. It tempts because it correlates email events across mailboxes, and would be correct for identifying which users received or clicked the phishing payload.
- ✗
Incident investigation in the Microsoft 365 Defender portal.
Why it's wrong here
Incident investigation aggregates alerts, evidence and remediation actions, but does not search mailbox contents or export messages. It tempts because it centralises response to the phishing campaign, and would be correct for triaging related alerts and containing compromised accounts rather than gathering email evidence.
- ✗
Mail Flow in the Exchange admin center.
Why it's wrong here
Mail Flow shows transport rules and message trace routing data, not mailbox contents, and cannot export messages for evidence. It tempts because it diagnoses delivery problems, and would be correct for tracing whether a phishing message was delivered, blocked or quarantined across the tenant.
- ✓
Content Search in the Microsoft Purview compliance portal.
Why this is correct
Content Search in Microsoft Purview queries multiple mailboxes simultaneously and exports matching messages to PST, satisfying the cross-mailbox collection requirement. Unlike eDiscovery holds or mailbox audit logging, it performs immediate, targeted searches across Exchange Online without placing mailboxes on hold, making it appropriate for rapid incident response collection.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.