SC-200 Respond to security incidents Practice Question
Which THREE actions should be taken when a phishing attack is detected in Microsoft Defender XDR?
⚠ Common exam trap
A common mix-up: candidates confuse the immediate containment actions (block sender, delete email) with post-compromise remediation steps (password reset, antivirus scan), leading them to select options that are appropriate only after a confirmed credential theft or malware infection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Report the email as phishing in Microsoft Defender for Office 365
Reporting the email as phishing in Microsoft Defender for Office 365 triggers automated investigation and remediation workflows, including tenant-level block actions and threat intelligence updates. This action directly supports the incident response process by enabling the security team to analyze the phishing attempt and prevent further delivery to other users.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Run a full antivirus scan on the user's device
Why it's wrong here
In a phishing incident, the initial threat is the email itself and potential credential compromise; an AV scan addresses malware on the endpoint, but phishing emails often don't deploy malware. The email may contain malicious links, not attachments, so scanning the device is reactive and doesn't stop the ongoing threat or remove the email. Also, Defender for Office 365 handles email-level threats, so AV scan is not a primary containment step.
- ✓
Report the email as phishing in Microsoft Defender for Office 365
Why this is correct
Reporting submits the email to Microsoft for analysis, which updates the threat intelligence and improves automated detection for the whole organization. In MDO, this can be done via the User-reported messages report or the built-in Report Message add-in. This action also allows the security team to investigate the incident and potentially automate remediation policies.
- ✗
Reset the user's password
Why it's wrong here
Password reset is only necessary if the user clicked a link and entered credentials. In a suspicious email, the immediate priority is to prevent its spread and block the attacker, not rotate the password preemptively. Unnecessary password resets may cause account lockouts and user disruption without addressing the root cause of the phishing email.
- ✓
Block the sender's email address or domain
Why this is correct
In MDO, you can block the sender by adding to the Tenant Allow/Block List or creating a mail flow rule. Blocking at domain/sender level stops additional emails from the same threat actor from reaching other users. This is a critical containment measure to halt the campaign.
- ✓
Delete the phishing email from the user's mailbox
Why this is correct
Deleting (or purging) the email removes the malicious payload from the mailbox, preventing repeat clicks or accidental interactions. In MDO, you can use the Threat Explorer and mailbox search to find and delete messages across the environment. This is an essential remediation step to ensure the user doesn't return to the email.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.