SC-200 Respond to security incidents Practice Question
You are investigating a Microsoft Sentinel incident involving a user who clicked a phishing link. The incident includes alerts from Microsoft Defender for Office 365. You need to identify if any other users received the same phishing email. What should you do?
⚠ Common exam trap
SC-200 often tests whether candidates pick the generic Sentinel tool (incident graph, timeline, or Advanced Hunting) when the scenario specifically requires email-centric recipient enumeration, which only Threat Explorer provides.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use the Threat Explorer in Microsoft Defender for Office 365
Threat Explorer in Microsoft Defender for Office 365 is the purpose-built tool for investigating email threats at scale — it lets you pivot on the phishing campaign's sender, URL, or message ID and see every recipient who received the same message. This is exactly the 'who else got this email' question. Sentinel's incident graph and timeline show correlated alerts but do not provide the email-centric recipient enumeration that Threat Explorer does.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Check the incident timeline for related alerts
Why it's wrong here
The incident timeline in Microsoft Sentinel is scoped to the current incident's aggregated alerts and activities only. It does not provide a mechanism to pivot into all email messages across the tenant, so it cannot reveal sibling phishing emails sent to other users or identify the full attack campaign. This makes it insufficient for determining how many recipients were exposed.
- ✗
Review the incident graph in Microsoft Sentinel
Why it's wrong here
The incident graph in Microsoft Sentinel visualizes relationships among entities—such as users, hosts, and IP addresses—that are already part of the current incident. It enriches the investigation context for that specific incident but does not query email telemetry across all mailboxes. Therefore, it cannot identify other users who received the same malicious email, which is the key investigative need.
- ✗
Run a KQL query in Advanced Hunting
Why it's wrong here
Advanced Hunting in Microsoft 365 Defender can indeed query email logs using tables like EmailEvents and EmailUrlInfo, but it requires writing and tuning a KQL query with schema knowledge. It is a raw hunting interface rather than a purpose-built email investigation tool, so it is slower and less direct for this exact task. Threat Explorer offers a guided UI and automatic correlation, making it the more appropriate choice.
- ✓
Use the Threat Explorer in Microsoft Defender for Office 365
Why this is correct
Threat Explorer (also known as Explorer) in Microsoft Defender for Office 365 is purpose-built for investigating email threats across all mailboxes. It allows searching by message ID, subject, sender, recipient, and delivery status, and can filter by detection technology, threat type, and campaign ID. This enables the analyst to quickly locate every copy of the phishing email, assess the blast radius, and take remediation actions directly.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.