Courseiva

SC-200 Respond to security incidents Practice Question

You are investigating an incident in Microsoft Defender XDR that involves a user who clicked a link in a phishing email. The email was detected and blocked by Microsoft Defender for Office 365, but the user still clicked the link before it was blocked. The incident includes an alert for 'Malicious URL click'. What additional information should you check to determine if the user's credentials were compromised?

⚠ Common exam trap

SC-200 often tests the distinction between a detection alert (the click) and a confirmed compromise indicator (an anomalous sign-in), tricking candidates into treating the alert itself as proof of credential theft.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Check for sign-in events from unusual locations or anonymous IP addresses after the click

The 'Malicious URL click' alert confirms the user interacted with the phishing link, but it does not confirm credential theft. The definitive indicator of compromise is a subsequent successful authentication using those credentials from an anomalous source. Checking Microsoft Entra ID sign-in logs (via Defender XDR's Advanced Hunting with AADSignInEventsBeta or the Entra sign-in log) for sign-ins from unusual geolocations, anonymous proxies (e.g., Tor exit nodes), or unfamiliar IPs immediately after the click timestamp reveals whether the attacker actually used the harvested credentials.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Check if the link was blocked by the time the user clicked

    Why it's wrong here

    Whether the URL was blocked at click time is already established by the 'Malicious URL click' alert itself, so it adds nothing about credential theft. It is tempting because block status confirms exposure, but determining compromise requires checking sign-in logs for anomalous authentication from the user's account.

  • ✓

    Check for sign-in events from unusual locations or anonymous IP addresses after the click

    Why this is correct

    Sign-in events from unusual locations or anonymous IP addresses after the click indicate whether stolen credentials were used. This telemetry, available through Microsoft Entra ID sign-in logs, confirms or rules out credential compromise following the malicious URL click.

  • ✗

    Check if the user has recently changed their password

    Why it's wrong here

    A recent password change does not indicate whether the phishing page harvested credentials; users change passwords for many unrelated reasons. It is tempting because password resets often follow compromise, but confirming credential theft requires reviewing Microsoft Entra ID sign-in logs for risky or anomalous authentication after the click.

  • ✗

    Check if the email had any attachments

    Why it's wrong here

    Attachment presence is irrelevant here because the incident concerns a clicked link, not a malicious file; attachments would matter only for a separate malware investigation. Checking them is tempting because phishing emails often carry payloads, but credential compromise is determined from post-click authentication activity in Microsoft Entra ID sign-in logs.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.