SC-200 Respond to security incidents Practice Question
During an incident response, you need to collect email messages from a user's mailbox in Microsoft 365 for evidence. The user is suspected of phishing. Which Microsoft Purview solution should you use?
⚠ Common exam trap
SC-200 often tests the confusion between Audit (which shows activity logs) and eDiscovery (which collects content) — candidates pick Audit thinking it retrieves emails, but it only shows metadata about mailbox operations.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
eDiscovery (Standard)
Microsoft Purview eDiscovery (Standard) is designed for identifying, collecting, and preserving electronically stored information (ESI) such as email messages for legal or investigative purposes. It supports mailbox searches, holds, and export of evidence, making it the correct tool for collecting a user's mailbox during incident response.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
eDiscovery (Standard)
Why this is correct
eDiscovery (Standard) supports searching, holding and exporting mailbox content for legal or investigative purposes, matching the need to collect email evidence. It preserves messages in place, so suspected phishing correspondence is captured without altering the user's mailbox.
- ✗
Data Loss Prevention
Why it's wrong here
Data Loss Prevention enforces policies that block or warn on sensitive content leaving the tenant; it cannot search a mailbox and export messages as evidence. It is tempting because both concern email content, and would be correct for preventing a user emailing confidential data externally, not for forensic collection.
- ✗
Records Management
Why it's wrong here
Records Management applies retention and disposal labels to declared business records; it neither searches a mailbox nor exports messages for legal or investigative review. It is tempting because both handle email retention, and would be correct for governing the lifecycle of regulatory records, not collecting phishing evidence.
- ✗
Audit (Standard)
Why it's wrong here
Audit (Standard) records user and admin activity in the audit log, letting you search events, but it does not copy mailbox messages into a reviewable evidence set. It is tempting because it traces the suspected phishing activity, and would be correct for investigating who did what, not gathering message content.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.