Courseiva
mediumMultiple Choice

SC-200 Practice Question: In Microsoft 365 Defender, a security analyst…

In Microsoft 365 Defender, a security analyst wants to get a detailed report on a newly discovered malware campaign, including indicators of compromise, recommended actions, and impacted devices. Where should the analyst go to find this information?

⚠ Common exam trap

Candidates often confuse the Incident page (which handles active investigations) with Threat analytics (which provides pre-built campaign intelligence and proactive guidance), leading them to select the Incident page for campaign details instead of the dedicated threat intelligence hub.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Threat analytics

Threat analytics in Microsoft 365 Defender provides detailed reports on active malware campaigns, including indicators of compromise (IoCs), recommended actions, and impacted devices. This is the dedicated workspace for tracking and responding to emerging threats, offering curated intelligence from Microsoft security researchers.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Alerts queue

    Why it's wrong here

    The Alerts queue is a listing of individual security alerts generated by detection logic across workloads like Microsoft Defender for Endpoint and Defender for Office 365. While it supports filtering, grouping, and manual triage, it shows each alert as a discrete event rather than synthesizing them into a broader campaign narrative. It lacks the threat-actor context, attack-chain visualization, and remediation guidance that a threat intelligence report provides, so it is not the correct place to obtain a comprehensive campaign overview.

  • ✗

    Incident page

    Why it's wrong here

    The Incident page in Microsoft 365 Defender aggregates related alerts, assets, and evidence for a specific intrusion or attack that has occurred in your environment. It is designed for incident response, offering an attack timeline and recommended actions for that one incident, but it does not pull in external threat intelligence about active campaigns affecting other organizations. Because its scope is bounded to your tenant's current detections, it cannot provide the proactive, global threat actor intelligence or mitigation guidance needed for a campaign-level view.

  • ✓

    Threat analytics

    Why this is correct

    Threat analytics is the correct choice because it is Microsoft's dedicated threat intelligence experience within Microsoft Defender XDR (formerly Microsoft 365 Defender). Each threat analytics report provides detailed analysis of an ongoing or impactful threat, including its attack methods (TTPs), associated indicators of compromise (IoCs), affected platforms, relevant CVE vulnerabilities, and concrete mitigation steps. The reports are curated by Microsoft researchers and are tied to the latest global threat activity, making them the authoritative source for understanding and responding to a broad threat campaign beyond just your own alerts.

  • ✗

    Action center

    Why it's wrong here

    The Action center is the management pane for completed, in-progress, and recommended remediation actions across Defender workloads, such as quarantining a malware sample or blocking a suspicious URL. It shows the status and details of these automated or manual response actions, but it does not contain threat intelligence reports, campaign context, or threat actor profiles. Its purpose is operational execution of mitigation steps, not discovery of new threat information, so it is wrong for obtaining a comprehensive campaign overview.

Visual reference

Client DHCP Server 1 Discover (broadcast) 2 Offer (IP: 192.168.1.10) 3 Request (I accept) 4 Acknowledge (lease confirmed) DORA — the four-step DHCP lease process

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.