SC-200 Respond to security incidents Practice Question
Your organization is using Microsoft Defender for Office 365. A user reports receiving a suspicious email that appears to be from the CEO requesting an urgent wire transfer. You need to investigate the email and take immediate action. What should you do first?
⚠ Common exam trap
Candidates often confuse the purpose of message traces (delivery tracking) with the immediate remediation capabilities of Threat Explorer, or they mistakenly think that creating a mail flow rule can retroactively remove already delivered emails.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use Threat Explorer in the Microsoft 365 Defender portal to find and delete the email.
Threat Explorer in the Microsoft 365 Defender portal provides the fastest and most direct way to investigate and remediate a specific suspicious email across all mailboxes. It allows you to search for the email by sender, subject, or recipient, and then take immediate action such as soft-delete or hard-delete to remove it from user inboxes. This is the correct first step for an urgent incident response scenario involving a targeted phishing attack.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use the Exchange admin center to run a message trace.
Why it's wrong here
Message trace in the Exchange admin center is a mail-flow diagnostic tool that returns delivery status and latency for a specific sender/recipient and time range. It does not scan user mailboxes for content, and it offers no action to purge a delivered email from recipients' mailboxes. Because the requirement is to locate and delete an already delivered email, message trace cannot satisfy the remediation step.
- ✓
Use Threat Explorer in the Microsoft 365 Defender portal to find and delete the email.
Why this is correct
Threat Explorer in the Microsoft 365 Defender portal is the actual investigation-and-remediation surface for email threats; it combines a robust queryable event store with built-in actions. You can filter by threat type, sender, subject, or detection technology, select one or multiple messages, and directly delete (soft or hard) them from user mailboxes. For a suspicious email already delivered, this is the only option that both finds and removes it. Also supports in-place review of the payload and email summary.
- ✗
Use the Security & Compliance Center to create a mail flow rule.
Why it's wrong here
Creating a mail flow rule in the Security & Compliance Center (now Purview portal) only applies to messages in transit that match the rule conditions at send/receive time. It has no effect on messages that have already been delivered to mailboxes, and its typical actions—such as redirect, reject, or BCC—do not include a 'delete existing message' capability. The rule might stop future occurrences, but it will not remediate the specific email in question.
- ✗
Submit the email to Microsoft for analysis using the Submissions page.
Why it's wrong here
The Submissions page is a feedback channel for sending suspected phishing or spam emails to Microsoft analysts for evaluation and to improve detection, not a quarantine or deletion tool. Submitting an email adds it to the Microsoft sample queue, but it does not take any action on the mailbox copy. Since the requirement is immediate deletion of the already-delivered message from the user's mailbox, the Submissions page is not a remediation mechanism.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.