SC-200 Respond to security incidents Practice Question
Your Microsoft 365 tenant is protected by Microsoft Defender for Office 365. A user reports receiving a suspicious email with a link. You need to investigate whether the link was malicious and if any other users clicked it. Which tool should you use first?
⚠ Common exam trap
Many candidates confuse the Email Entity page (which shows details for a single email) with Threat Explorer (which provides aggregated, searchable data across all emails and clicks), leading them to pick Option C instead of the correct tool for multi-user investigation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Threat Explorer
Threat Explorer (Option D) is the correct first tool because it provides a centralized view of email threats, including malicious links and clicks. You can filter by URL or sender to identify if the specific link was detected as malicious and then use the 'Click to allow/block' feature or the 'URL clicks' view to see which users clicked it. This aligns with the incident response workflow for investigating phishing campaigns in Defender for Office 365.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Entra ID sign-in logs
Why it's wrong here
Microsoft Entra ID sign-in logs record authentication and sign-in events for user access to cloud apps, but they do not capture email message metadata, delivery status, or user interaction with URLs embedded in email messages. Therefore they lack the granular email threat data needed to investigate a phishing click, where you need recipient-level mailbox details and URL threat verdicts. While sign-in logs can indicate a user's token or conditional access, they don't reveal whether a user clicked a malicious link in a specific email.
- ✗
Microsoft Purview compliance portal
Why it's wrong here
The Microsoft Purview compliance portal is focused on data lifecycle management, eDiscovery, audit, records retention, and regulatory compliance policies, not on live email security investigations. Although it provides audit logs that can be used to trace administrative activity, it does not expose the email threat telemetry needed to query for specific URL clicks or malware verdicts per message. Security teams must use Defender for Office 365 tools like Threat Explorer to correlate threat detections with user behavior, as compliance portals do not ingest Safe Links or delivery-action data.
- ✗
Email Entity page in Microsoft Defender XDR
Why it's wrong here
The Email Entity page in Microsoft Defender XDR presents a forensic snapshot of a single email message, including its delivery location, IP details, and system overrides, but it is designed for one-off message inspection rather than aggregate analysis. It cannot run queries across multiple messages or summarize click activity for a specific URL across many users. To determine how many users clicked a malicious link in a campaign, you need a queryable data source like Threat Explorer, which offers a URL view showing click data aggregated by user and time.
- ✓
Threat Explorer
Why this is correct
Threat Explorer is the correct tool because it is a security hunting and investigation engine built into Microsoft Defender for Office 365 that provides queryable access to email message data and user click activities. It includes a dedicated URL view that reports each click on a Safe Links-protected URL, the identity of the user who clicked it, the verdict applied, and the client app used, with the ability to filter by time, user, and threat type. This makes it ideal for investigating a potential phishing click and correlating it with email delivery and threat intelligence.
- ✗
Attack Simulation Training
Why it's wrong here
Attack Simulation Training in Microsoft Defender XDR is a user-awareness platform that creates controlled phishing simulations to measure susceptibility and educate employees, but it does not collect operational email security data from the live environment. Its reports show simulation results, such as who clicked simulated phishing links, but those clicks are not real threats and are not derived from Defender's actual email scanning pipeline. Thus, it is a testing tool, not an investigation tool for real-world email threats, which require Threat Explorer's telemetry.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.