SC-200 Respond to security incidents Practice Question
You are investigating a low-severity incident in Microsoft Sentinel where a user reported receiving a phishing email. The email was not blocked by the email security solution. The user did not click any links. What should you do first?
⚠ Common exam trap
SC-200 often tests the order of operations in incident response — candidates jump to remediation (delete, reset, isolate) instead of the correct first step of analysis/reporting, especially when the user did not click.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Report the email for analysis using the Microsoft 365 Defender portal
The first step is to report the email for analysis using the Microsoft 365 Defender portal. Since the email was not blocked and the user did not click any links, the immediate priority is to submit the message to Microsoft for analysis (via the Submissions page or the Report button) so that detections can be tuned and the sender/URLs can be blocked if malicious. This preserves evidence and improves organizational protection before taking remediation actions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Delete the phishing email from the user's inbox
Why it's wrong here
Deleting the phishing email from the user's inbox destroys the primary forensic artifact: the original message, its Internet headers, and associated metadata that are essential for tracing the attack chain, extracting indicators of compromise (IOCs), and correlating with other detections. Rather than removing the message, you should preserve it by placing it on an eDiscovery hold or submitting it for analysis, because deletion also fails to remediate the same phishing email if it remains in other mailboxes or in the tenant's quarantine.
- ✓
Report the email for analysis using the Microsoft 365 Defender portal
Why this is correct
Reporting the email via the Microsoft 365 Defender portal (using the 'Report a message' or admin submission workflow) submits the original email, including its headers and attachments, to Microsoft's automated detonation and analysis systems. This enables the security team to extract actionable IOCs, update tenant-level block and allow lists, and contribute to global filtering improvements—directly addressing the low-severity phishing incident without destroying evidence. It is the correct initial response because it simultaneously preserves the artifact and enhances email security posture.
- ✗
Reset the user's password as a precaution
Why it's wrong here
Resetting the user's password without evidence of account compromise or successful credential theft is an unnecessary and disruptive precaution that can cause unnecessary user downtime and secondary support incidents. In a low-severity phishing case where the user only reported the email and no threat actor authentication or token replay has been detected, password reset is not warranted by the current evidence. Instead, the incident playbook dictates monitoring for post-click indicators, and a password reset should be deferred until a confirmed compromise or user-entered credential attempt is discovered.
- ✗
Isolate the user's device from the network
Why it's wrong here
Isolating the user's device from the network is a containment action reserved for confirmed malware infections, active command-and-control communication, or post-exploitation behavior—none of which apply to a low-severity phishing email that was simply reported. Network isolation would sever the device's access to corporate resources, impeding the investigation's ability to gather telemetry and logs, while providing no benefit because no malicious execution or infection has been indicated. If device compromise is suspected, you should instead use Microsoft Defender for Endpoint to check for alerts and only initiate isolation upon clear evidence of a threat.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.