SC-200 Respond to security incidents Practice Question
You are investigating a phishing incident in Microsoft Defender XDR. The user reported receiving an email with a malicious link. You need to identify all users who received the same email. Which feature should you use?
⚠ Common exam trap
SC-200 often tests the distinction between investigation tools — candidates confuse Advanced Hunting (raw KQL queries) with Threat Explorer (purpose-built email investigation UI), even though both can technically surface email data.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Threat Explorer
Threat Explorer (part of Microsoft Defender for Office 365 / Defender XDR) is purpose-built for email and collaboration threat investigation. It lets you pivot on a malicious URL, sender, or message and see every recipient who received the same email, along with delivery status and remediation actions. This is the correct tool for identifying the blast radius of a phishing campaign.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Automation & investigations
Why it's wrong here
Automation & investigations in Microsoft 365 Defender manages automated response playbooks and remediation actions such as quarantining or blocking entities after a threat is detected, but it does not index or search raw mail flow items. It works on alerts and incidents, not on message telemetry, so a security analyst cannot use it to locate phishing email by sender, recipient, subject, or delivery status. This is why it is not the correct tool for a direct email search; it is for orchestrating responses, not forensic investigation of message history.
- ✗
Incidents view
Why it's wrong here
The Incidents view aggregates related alerts, assets, and evidence into a single case, but it presents a summarized correlation rather than allowing the investigator to perform granular email-level searches. Although an incident may show the affected mailbox or a link to related messages, it lacks the search filters needed to trace phishing emails by message ID, header, or delivery action. It is designed for triage and investigation management, not as a message-search utility, making it incorrect for this phishing investigation step.
- ✓
Threat Explorer
Why this is correct
Threat Explorer is the dedicated email-trace and forensics tool in Microsoft 365 Defender, purpose-built for investigating malicious mail across Exchange Online and Microsoft Defender for Office 365. It supports near real-time searches and filters by sender, recipient, subject, message ID, detection technology, delivery status, and header data, and it can even display email headers for detailed verification. Because it lets analysts immediately pivot from search results to remediation actions such as soft-deleting from mailboxes, it is the correct surfacing feature for phishing email investigation.
- ✗
Advanced Hunting
Why it's wrong here
Advanced Hunting is a Kusto Query Language (KQL) interface over a broad schema, including EmailEvents and EmailUrlInfo, that requires writing custom queries for email investigations. It is not a direct email-search feature like Threat Explorer because it lacks a simplified form-based message trace workflow and does not inherently show message headers or offer one-click email remediation actions. While it can uncover complex relationships by joining email, identity, and device tables, choosing it for a basic phishing trace would be less efficient and outside the intuition of this question.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SC-200
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. You are investigating a phishing incident in Microsoft Defender XDR. The incident involves a user who clicked a malicious link in an email. Which data source would you use to trace the email's origin?
easy- A.Microsoft Defender for Endpoint
- ✓ B.Microsoft Defender for Office 365
- C.Microsoft Defender for Cloud Apps
- D.Microsoft Defender for Identity
Why B: Microsoft Defender for Office 365 (MDO) is the correct data source because it provides email-specific telemetry, including SMTP headers, sender IP addresses, and authentication results (SPF, DKIM, DMARC). This data is essential for tracing the origin of a phishing email that a user clicked. MDO's Threat Explorer and Email Entity page allow you to reconstruct the email's path from the sending server to the recipient's inbox.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.