SC-200 Respond to security incidents Practice Question
You are investigating an incident in Microsoft Defender XDR that involves a user who clicked a link in a phishing email. The email was detected and blocked by Microsoft Defender for Office 365, but the user still clicked the link before it was blocked. The incident includes an alert for 'Malicious URL click'. What additional information should you check to determine if the user's credentials were compromised?
⚠ Common exam trap
SC-200 often tests the distinction between a detection alert (the click) and a confirmed compromise indicator (an anomalous sign-in), tricking candidates into treating the alert itself as proof of credential theft.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Check for sign-in events from unusual locations or anonymous IP addresses after the click
The 'Malicious URL click' alert confirms the user interacted with the phishing link, but it does not confirm credential theft. The definitive indicator of compromise is a subsequent successful authentication using those credentials from an anomalous source. Checking Microsoft Entra ID sign-in logs (via Defender XDR's Advanced Hunting with AADSignInEventsBeta or the Entra sign-in log) for sign-ins from unusual geolocations, anonymous proxies (e.g., Tor exit nodes), or unfamiliar IPs immediately after the click timestamp reveals whether the attacker actually used the harvested credentials.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Check if the link was blocked by the time the user clicked
Why it's wrong here
Whether the URL was blocked at click time is already established by the 'Malicious URL click' alert itself, so it adds nothing about credential theft. It is tempting because block status confirms exposure, but determining compromise requires checking sign-in logs for anomalous authentication from the user's account.
- ✓
Check for sign-in events from unusual locations or anonymous IP addresses after the click
Why this is correct
Sign-in events from unusual locations or anonymous IP addresses after the click indicate whether stolen credentials were used. This telemetry, available through Microsoft Entra ID sign-in logs, confirms or rules out credential compromise following the malicious URL click.
- ✗
Check if the user has recently changed their password
Why it's wrong here
A recent password change does not indicate whether the phishing page harvested credentials; users change passwords for many unrelated reasons. It is tempting because password resets often follow compromise, but confirming credential theft requires reviewing Microsoft Entra ID sign-in logs for risky or anomalous authentication after the click.
- ✗
Check if the email had any attachments
Why it's wrong here
Attachment presence is irrelevant here because the incident concerns a clicked link, not a malicious file; attachments would matter only for a separate malware investigation. Checking them is tempting because phishing emails often carry payloads, but credential compromise is determined from post-click authentication activity in Microsoft Entra ID sign-in logs.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.