SC-200 Respond to security incidents Practice Question
You are investigating a phishing incident in Microsoft Defender XDR. The incident involves a user who clicked a malicious link in an email. Which data source would you use to trace the email's origin?
⚠ Common exam trap
Test-takers frequently confuse Microsoft Defender for Endpoint's network-level visibility (e.g., URL click events) with the email-specific origin data that only Microsoft Defender for Office 365 can provide.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Defender for Office 365
Microsoft Defender for Office 365 (MDO) is the correct data source because it provides email-specific telemetry, including SMTP headers, sender IP addresses, and authentication results (SPF, DKIM, DMARC). This data is essential for tracing the origin of a phishing email that a user clicked. MDO's Threat Explorer and Email Entity page allow you to reconstruct the email's path from the sending server to the recipient's inbox.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Defender for Endpoint
Why it's wrong here
Microsoft Defender for Endpoint is an endpoint-based solution that collects telemetry from devices, including processes, file hashes, and network connections, to detect and respond to threats on the endpoint. Its scope does not extend to the email transport pipeline or Exchange Online mailbox artifacts, so the original phishing message, sender spoofing, or URL detonation in email context is not visible here. While it can analyze post-compromise activity like a payload executed from a phishing link, it is not the primary data source for investigating the phishing incident itself.
- ✓
Microsoft Defender for Office 365
Why this is correct
Microsoft Defender for Office 365 is the correct tool because it natively monitors email flow and protects Exchange Online through threat policies, URL detonation, and attachment sandboxing. It exposes rich hunting telemetry in Threat Explorer, such as email delivery outcomes, URL click verdicts, and user-reported phishing submissions, along with the ability to trace a message's complete path. This direct visibility into the phishing email's origin, targeting, and verdicts makes it the proper investigative surface for a phishing incident. It may later inform pivots to other Defender workloads, but initial triage belongs here.
- ✗
Microsoft Defender for Cloud Apps
Why it's wrong here
Microsoft Defender for Cloud Apps is a cloud access security broker (CASB) that specializes in monitoring user sessions, shadow IT discovery, and data governance across SaaS applications like SharePoint, OneDrive, and third-party cloud apps. It does not ingest the mail transport logs or email header metadata required to identify how a phishing email was delivered or whether it was quarantined. Its value in a phishing scenario is limited to detecting abnormal access or suspicious activity if a user's credentials were compromised after the phishing succeeds, rather than investigating the email itself.
- ✗
Microsoft Defender for Identity
Why it's wrong here
Microsoft Defender for Identity is anchored to on-premises Active Directory, analyzing authentication events, Kerberos tickets, and domain controller traffic to detect attacks like pass-the-hash and lateral movement. It has no visibility into Exchange Online mail transport or message content, so a phishing email would not appear in its signal set. Its usefulness emerges later in the attack chain if the phished credentials are used against the on-premises domain, but it does not contribute to the initial email investigation.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.