Courseiva

SC-200 Respond to security incidents Practice Question

During an incident response, you need to collect email messages from a user's mailbox in Microsoft 365 for evidence. The user is suspected of phishing. Which Microsoft Purview solution should you use?

⚠ Common exam trap

SC-200 often tests the confusion between Audit (which shows activity logs) and eDiscovery (which collects content) — candidates pick Audit thinking it retrieves emails, but it only shows metadata about mailbox operations.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

eDiscovery (Standard)

Microsoft Purview eDiscovery (Standard) is designed for identifying, collecting, and preserving electronically stored information (ESI) such as email messages for legal or investigative purposes. It supports mailbox searches, holds, and export of evidence, making it the correct tool for collecting a user's mailbox during incident response.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    eDiscovery (Standard)

    Why this is correct

    eDiscovery (Standard) supports searching, holding and exporting mailbox content for legal or investigative purposes, matching the need to collect email evidence. It preserves messages in place, so suspected phishing correspondence is captured without altering the user's mailbox.

  • ✗

    Data Loss Prevention

    Why it's wrong here

    Data Loss Prevention enforces policies that block or warn on sensitive content leaving the tenant; it cannot search a mailbox and export messages as evidence. It is tempting because both concern email content, and would be correct for preventing a user emailing confidential data externally, not for forensic collection.

  • ✗

    Records Management

    Why it's wrong here

    Records Management applies retention and disposal labels to declared business records; it neither searches a mailbox nor exports messages for legal or investigative review. It is tempting because both handle email retention, and would be correct for governing the lifecycle of regulatory records, not collecting phishing evidence.

  • ✗

    Audit (Standard)

    Why it's wrong here

    Audit (Standard) records user and admin activity in the audit log, letting you search events, but it does not copy mailbox messages into a reviewable evidence set. It is tempting because it traces the suspected phishing activity, and would be correct for investigating who did what, not gathering message content.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.