Courseiva

SC-200 Respond to security incidents Practice Question

You are investigating a phishing incident in Microsoft Defender XDR. The incident involves a user who clicked a malicious link in an email. Which data source would you use to trace the email's origin?

⚠ Common exam trap

Test-takers frequently confuse Microsoft Defender for Endpoint's network-level visibility (e.g., URL click events) with the email-specific origin data that only Microsoft Defender for Office 365 can provide.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Defender for Office 365

Microsoft Defender for Office 365 (MDO) is the correct data source because it provides email-specific telemetry, including SMTP headers, sender IP addresses, and authentication results (SPF, DKIM, DMARC). This data is essential for tracing the origin of a phishing email that a user clicked. MDO's Threat Explorer and Email Entity page allow you to reconstruct the email's path from the sending server to the recipient's inbox.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Microsoft Defender for Endpoint

    Why it's wrong here

    Microsoft Defender for Endpoint is an endpoint-based solution that collects telemetry from devices, including processes, file hashes, and network connections, to detect and respond to threats on the endpoint. Its scope does not extend to the email transport pipeline or Exchange Online mailbox artifacts, so the original phishing message, sender spoofing, or URL detonation in email context is not visible here. While it can analyze post-compromise activity like a payload executed from a phishing link, it is not the primary data source for investigating the phishing incident itself.

  • ✓

    Microsoft Defender for Office 365

    Why this is correct

    Microsoft Defender for Office 365 is the correct tool because it natively monitors email flow and protects Exchange Online through threat policies, URL detonation, and attachment sandboxing. It exposes rich hunting telemetry in Threat Explorer, such as email delivery outcomes, URL click verdicts, and user-reported phishing submissions, along with the ability to trace a message's complete path. This direct visibility into the phishing email's origin, targeting, and verdicts makes it the proper investigative surface for a phishing incident. It may later inform pivots to other Defender workloads, but initial triage belongs here.

  • ✗

    Microsoft Defender for Cloud Apps

    Why it's wrong here

    Microsoft Defender for Cloud Apps is a cloud access security broker (CASB) that specializes in monitoring user sessions, shadow IT discovery, and data governance across SaaS applications like SharePoint, OneDrive, and third-party cloud apps. It does not ingest the mail transport logs or email header metadata required to identify how a phishing email was delivered or whether it was quarantined. Its value in a phishing scenario is limited to detecting abnormal access or suspicious activity if a user's credentials were compromised after the phishing succeeds, rather than investigating the email itself.

  • ✗

    Microsoft Defender for Identity

    Why it's wrong here

    Microsoft Defender for Identity is anchored to on-premises Active Directory, analyzing authentication events, Kerberos tickets, and domain controller traffic to detect attacks like pass-the-hash and lateral movement. It has no visibility into Exchange Online mail transport or message content, so a phishing email would not appear in its signal set. Its usefulness emerges later in the attack chain if the phished credentials are used against the on-premises domain, but it does not contribute to the initial email investigation.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.