Courseiva

SC-200 Manage a security operations environment Practice Question

Your organization has Microsoft Defender for Office 365. You need to review a user's reported phishing email in Microsoft Defender XDR. Which section of the Microsoft Defender portal should you check?

⚠ Common exam trap

A common mix-up: candidates confuse the Submissions page (for user-reported messages) with Threat Explorer (for querying historical threat data), leading them to choose B instead of A.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Submissions

The Submissions page in the Microsoft Defender portal is the dedicated section for reviewing user-reported phishing emails. It allows security operators to view, analyze, and take action on messages that users have reported as suspicious or malicious, directly integrating with Microsoft Defender for Office 365's threat intelligence pipeline.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Submissions

    Why this is correct

    The Submissions page in Microsoft Defender XDR is the centralized, dedicated queue for user-reported messages, surfaced through the Report Message and Report Phishing add-ins in Outlook. It provides security admins with the message details, report type, and source, and allows them to triage, analyze, and take remediation actions such as release, purge, or submit to Microsoft for analysis. This page is the only location specifically designed to display what users have manually flagged, making it the correct place to find user-reported messages.

  • ✗

    Threat Explorer

    Why it's wrong here

    Threat Explorer is a powerful, real-time and historical hunting tool used to investigate threats such as malware, phishing, and delivery anomalies across emails and content. It does not natively show user-reported submissions; instead, it relies on threat intelligence and detection signals, and requires an admin to build custom queries to correlate data back to user reports. Its purpose is deep threat investigation, not to provide a direct view of messages sent through the Outlook report add-in, so it is the wrong interface for this task.

  • ✗

    Alerts

    Why it's wrong here

    The Alerts page in Microsoft Defender XDR presents system-generated security alerts from detection rules, signifying suspicious entities, activities, or incidents that require investigation. User-reported messages do not automatically generate an alert unless an admin explicitly creates a custom detection or policy to trigger one, and even then, the alert would not show the raw submission queue. Because the alerting pipeline is distinct from the user-reported message pipeline, this page provides no direct access to user submissions.

  • ✗

    Action center

    Why it's wrong here

    The Action center in Microsoft Defender XDR shows pending and completed remediation actions, such as soft-delete, hard-delete, quarantine, or automated investigation responses that were applied after a threat was identified. It does not display the original user-reported messages themselves; instead, it tracks the actions taken on messages after they have already been processed and investigated. The Submissions page exists upstream of any remediation action, so the Action center is not where an admin goes to see what users have submitted.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.