Courseiva

SC-200 Respond to security incidents Practice Question

You are investigating a low-severity incident in Microsoft Sentinel where a user reported receiving a phishing email. The email was not blocked by the email security solution. The user did not click any links. What should you do first?

⚠ Common exam trap

SC-200 often tests the order of operations in incident response — candidates jump to remediation (delete, reset, isolate) instead of the correct first step of analysis/reporting, especially when the user did not click.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Report the email for analysis using the Microsoft 365 Defender portal

The first step is to report the email for analysis using the Microsoft 365 Defender portal. Since the email was not blocked and the user did not click any links, the immediate priority is to submit the message to Microsoft for analysis (via the Submissions page or the Report button) so that detections can be tuned and the sender/URLs can be blocked if malicious. This preserves evidence and improves organizational protection before taking remediation actions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Delete the phishing email from the user's inbox

    Why it's wrong here

    Deleting the phishing email from the user's inbox destroys the primary forensic artifact: the original message, its Internet headers, and associated metadata that are essential for tracing the attack chain, extracting indicators of compromise (IOCs), and correlating with other detections. Rather than removing the message, you should preserve it by placing it on an eDiscovery hold or submitting it for analysis, because deletion also fails to remediate the same phishing email if it remains in other mailboxes or in the tenant's quarantine.

  • ✓

    Report the email for analysis using the Microsoft 365 Defender portal

    Why this is correct

    Reporting the email via the Microsoft 365 Defender portal (using the 'Report a message' or admin submission workflow) submits the original email, including its headers and attachments, to Microsoft's automated detonation and analysis systems. This enables the security team to extract actionable IOCs, update tenant-level block and allow lists, and contribute to global filtering improvements—directly addressing the low-severity phishing incident without destroying evidence. It is the correct initial response because it simultaneously preserves the artifact and enhances email security posture.

  • ✗

    Reset the user's password as a precaution

    Why it's wrong here

    Resetting the user's password without evidence of account compromise or successful credential theft is an unnecessary and disruptive precaution that can cause unnecessary user downtime and secondary support incidents. In a low-severity phishing case where the user only reported the email and no threat actor authentication or token replay has been detected, password reset is not warranted by the current evidence. Instead, the incident playbook dictates monitoring for post-click indicators, and a password reset should be deferred until a confirmed compromise or user-entered credential attempt is discovered.

  • ✗

    Isolate the user's device from the network

    Why it's wrong here

    Isolating the user's device from the network is a containment action reserved for confirmed malware infections, active command-and-control communication, or post-exploitation behavior—none of which apply to a low-severity phishing email that was simply reported. Network isolation would sever the device's access to corporate resources, impeding the investigation's ability to gather telemetry and logs, while providing no benefit because no malicious execution or infection has been indicated. If device compromise is suspected, you should instead use Microsoft Defender for Endpoint to check for alerts and only initiate isolation upon clear evidence of a threat.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.