SC-200 Manage a security operations environment Practice Question
You are investigating a phishing incident in Microsoft Defender for Office 365. Which THREE pieces of information are available in the Threat Explorer?
⚠ Common exam trap
The SC-200 exam often tests the misconception that Threat Explorer provides full email body content or mailbox audit logs, when in reality it only exposes metadata and delivery actions, not the actual message body or user-level audit events.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Sender IP address
Sender IP address is available in Threat Explorer because it is a core property of email message trace data in Microsoft Defender for Office 365. Threat Explorer captures the originating IP address from the SMTP session header, which is essential for identifying the source of a phishing attack and correlating with threat intelligence feeds.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Email body content
Why it's wrong here
Threat Explorer indexes message envelope, header, and delivery metadata, not the actual MIME body content. The body is not a searchable field within the Explorer UI because its primary purpose is to expose threat-based findings and routing details. To inspect the body of a particular message, an investigator would need to use eDiscovery or Content Search, which access the mailbox item itself.
- ✗
User's mailbox audit log
Why it's wrong here
Mailbox audit logs record user and admin actions on the mailbox, such as message moves, folder bindings, or deletions, and are written to the MailboxAuditLog in Exchange Online. These logs are queried through the unified audit log or Export-MailboxAuditLog, not through Threat Explorer, which instead combines threat intelligence, message trace, and delivery data. For an attacker's sending IP, this source is irrelevant and would not contain the transport-level information.
- ✓
Sender IP address
Why this is correct
In Threat Explorer, each message record exposes the SenderIP property, populated from transport-level message tracking data (e.g., MessageTrace). This property is directly filterable in the UI, enabling investigators to pivot on the exact IPv4 or IPv6 address that originated the message. Because the question asks which finding could be used to attribute the message to a source host, Sender IP is a legitimate and expected column in Threat Explorer.
- ✓
Delivery action (e.g., blocked, delivered to Junk)
Why this is correct
Delivery action is a core column in Threat Explorer that shows the outcome of the message at the time of delivery, such as Delivered, Junked, Blocked, or Quarantined. This value is derived from the mail flow and policy evaluation pipeline, and it is one of the first identifiers analysts use to determine whether a phishing attempt reached the user's inbox. Thus, it is a correct answer because it is definitely present in Threat Explorer.
- ✓
Email subject and sender address
Why this is correct
Threat Explorer exposes email properties such as Subject and SenderAddress (the SMTP address of the sender) as part of its default message view. These fields come from message metadata and are essential for correlating multiple messages from the same campaign or identifying whether a user received the phishing email. Since these are standard indexed properties, they are also correct answers for what can be found in Threat Explorer.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.