SC-200 Respond to security incidents Practice Question
Which TWO actions should an analyst take when triaging a Microsoft Sentinel incident that involves a user who clicked a malicious link in a phishing email? (Choose two.)
⚠ Common exam trap
The trap is confusing triage with remediation; candidates may select actions like resetting passwords or deleting emails, which are remediation steps, rather than investigative steps like querying logs and checking threat explorer.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Run a KQL query on EmailEvents to identify the email and recipient.
Option C is correct because running a KQL query against the EmailEvents table in Microsoft Sentinel (or Advanced Hunting) lets the analyst locate the exact phishing message and confirm the recipient, delivery time, and network message ID, which is essential for scoping the incident. Option E is correct because Microsoft Defender for Office 365 Threat Explorer provides the email's current status (e.g., delivered, blocked, quarantined) and allows further investigation such as viewing the message header, URL detonation results, and related campaigns. Option A is not the right first triage action because a password reset is only warranted if credential compromise is confirmed, and doing it blindly can disrupt the user without addressing the email threat. Option B is not appropriate during triage because blocking the sender's domain tenant-wide is a containment/remediation step that should follow confirmation of the malicious domain and may cause false positives. Option D is also not a triage action; deleting the email is remediation, and it should be performed after confirming the message is malicious and after preserving evidence for the investigation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Reset the user's password immediately.
Why it's wrong here
Resetting the password is remediation for confirmed credential compromise, not triage; the analyst must first investigate whether credentials were actually harvested. It tempts because phishing often leads to account takeover, but immediate reset without evidence disrupts the user and skips the investigation step.
- ✗
Block the sender's domain in the tenant's block list.
Why it's wrong here
Blocking the sender domain is a containment step taken after triage establishes the threat, not part of triaging the incident itself. It tempts because domain blocking does prevent repeat delivery, but triage first requires investigating the alert and identifying affected users and indicators.
- ✓
Run a KQL query on EmailEvents to identify the email and recipient.
Why this is correct
Querying EmailEvents in Microsoft Sentinel's advanced hunting tables returns the specific email, recipient, delivery action and verdict, tying the phishing message to the affected user. This satisfies the stem's triage requirement by scoping the incident to concrete evidence before remediation.
- ✗
Delete the email from the user's mailbox immediately.
Why it's wrong here
Deleting the email is a remediation action, not triage; triage prioritises investigating the incident and containing the threat. It tempts because removing the phishing message does limit further clicks, but mailbox purge belongs to later response, after the analyst has assessed scope and affected users.
- ✓
Check the email's status in Microsoft Defender for Office 365 Threat Explorer.
Why this is correct
Threat Explorer shows the email's delivery action, detection verdict and any post-delivery remediation in Microsoft Defender for Office 365, confirming whether the malicious link was blocked, delivered or purged. This satisfies the stem's triage requirement by establishing the email's actual status before containment decisions.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.