Courseiva
mediumMultiple Choice

SC-200 Practice Question: During an incident investigation in Microsoft 365…

During an incident investigation in Microsoft 365 Defender, an analyst examines an email that was reported as phishing. The analyst opens the email entity page and looks at the 'Detection details' section. Which piece of information would the analyst find there?

⚠ Common exam trap

Many exam-takers confuse the 'Detection details' section with other sections like 'Summary' or 'Authentication', leading them to select options that describe information found elsewhere on the email entity page.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The detection technology (e.g., Advanced ML, Reputation) and if the email was part of a phish simulation or a campaign.

The 'Detection details' section on the email entity page in Microsoft 365 Defender specifically shows the detection technology used (e.g., Advanced ML, Reputation, Bulk) and whether the email was part of a phishing simulation or a campaign. This information helps analysts understand how the email was identified as malicious and its context within broader threat activity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The delivery location and whether the email was delivered to Inbox, Junk, or Quarantine.

    Why it's wrong here

    Delivery location (Inbox, Junk, or Quarantine) is a post-delivery outcome, not a detection signal. In Microsoft 365 Defender, this information appears on the Summary tab of the email entity page, which aggregates delivery verdicts and policy actions. The Detection details tab, by contrast, is specifically scoped to the threat identification logic—such as which detection stack or rule fired—not where the message ultimately landed.

  • ✗

    The authentication statuses (SPF, DKIM, DMARC) for the sender domain.

    Why it's wrong here

    Authentication statuses (SPF, DKIM, DMARC) evaluate sender identity and are displayed under the Authentication details tab on the email entity page, alongside cryptographic signatures and composite authentication results. Detection details, in contrast, reveal why Defender classified the email as malicious—such as a specific ML model or reputation verdict—not the email's authentication posture. A fully authenticated message can still be flagged as phishing based on content, sender reputation, or URL detonation.

  • ✗

    The sender IP address and the recipient email address.

    Why it's wrong here

    Sender IP address and recipient email address are transport-level metadata, not detection logic. The sender IP is typically extracted from Internet headers or the Message tab, while the recipient address is a property on the Summary tab. Detection details focus on the engine's reasoning for flagging the email—e.g., the specific detection technology or campaign association—not envelope fields like IPs and mailbox identifiers.

  • ✓

    The detection technology (e.g., Advanced ML, Reputation) and if the email was part of a phish simulation or a campaign.

    Why this is correct

    Correct. The Detection details tab in Microsoft 365 Defender discloses the precise detection technology that flagged the email—such as Advanced ML, Reputation, or a custom allow/block rule—along with whether the email is part of a phishing simulation campaign or a broader campaign. This tab is distinct from Summary (delivery outcome), Authentication details (SPF/DKIM/DMARC), and Message or Internet headers (transport metadata). For incident investigators, it is the authoritative source for understanding why Defender considered the email malicious, enabling quick triage of genuine threats versus simulation traffic.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.