Courseiva

SC-200 Manage a security operations environment Practice Question

You are a SOC analyst using Microsoft Defender XDR. You notice that a user's account has been compromised and is being used to send phishing emails. You need to prevent the user from sending any more emails while preserving the ability to receive emails for investigation. What should you do?

⚠ Common exam trap

Test-takers frequently confuse disabling the user account (which blocks all access) with a targeted email restriction, or they assume removing the license is a quick fix, not realizing it also stops email reception critical for investigation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Restrict the user from sending email using Microsoft Defender for Office 365 mailbox restrictions.

Microsoft Defender for Office 365 mailbox restrictions allow you to block a user from sending email while still permitting them to receive messages. This is done via the 'Restrict user from sending email' policy in the Microsoft 365 Defender portal, which applies a transport rule that rejects outbound mail from the user but leaves inbound delivery intact, enabling forensic analysis of incoming phishing responses.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Remove the user's Microsoft 365 license.

    Why it's wrong here

    Removing the user's Microsoft 365 license is an overly broad containment action that revokes the user's entitlement to Exchange Online and other services. This disables the mailbox entirely, so the user can neither send nor receive email, which disrupts the investigation and may trigger data retention or soft-delete states. License removal is not a targeted control for stopping malicious outbound email while preserving visibility into inbound messages.

  • ✗

    Disable the user account in Microsoft Entra ID.

    Why it's wrong here

    Disabling the user account in Microsoft Entra ID blocks all sign-in attempts across every integrated application, including Outlook on the web and mobile clients. While this effectively stops email sending, it also prevents the user from accessing their inbox, so you cannot monitor incoming phishing or attacker replies during the investigation. Account disabling is a tenant-wide identity control, not a mailbox-specific restriction, and it also halts other services such as Teams and SharePoint.

  • ✓

    Restrict the user from sending email using Microsoft Defender for Office 365 mailbox restrictions.

    Why this is correct

    Use the mailbox restriction feature in Microsoft Defender for Office 365 (or the corresponding Exchange Online mail flow rule) to place a targeted 'Restrict sending' action on the user. This blocks only outbound email — both to internal and external recipients — while the user can still receive email, allowing you to continue monitoring for malicious replies or C2 activity. This is the recommended containment step for a compromised account that is sending spam or phishing, because it balances security with the ability to investigate.

  • ✗

    Delete the user's mailbox in Exchange Online.

    Why it's wrong here

    Deleting the user's mailbox in Exchange Online is a destructive and irreversible action that purges all mailbox content, including messages and folder structure, and it cannot be easily restored unless a litigation hold or eDiscovery hold is in place. It eliminates the ability to send or receive email because the mailbox object no longer exists, and it destroys potential evidence needed for the incident investigation. Mailbox deletion is a last-resort administrative action, never used for active containment.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.