Courseiva

SC-200 Respond to security incidents Practice Question

Your organization uses Microsoft 365 Defender. An incident is created for a user who received a phishing email that contained a link to a malicious website. The user clicked the link but did not enter any credentials. The incident includes the alert 'Phishing delivered' from Microsoft Defender for Office 365. You need to remediate the incident and prevent future occurrences. The user is in the Finance department and frequently receives emails from external vendors. What is the best course of action?

⚠ Common exam trap

SC-200 often tests the difference between reactive reporting and active remediation—candidates pick 'report to Microsoft' or 'train the user' because they sound responsible, but the exam rewards the option that removes the threat and blocks the vector.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use Threat Explorer to delete the email from the user's mailbox and create a Safe Links policy to block the malicious URL.

The best remediation combines immediate containment with prevention: Threat Explorer (or the unified action center) lets you soft-delete or hard-delete the phishing email from the user's mailbox, and a Safe Links policy blocks the malicious URL so future clicks are neutralized. This addresses both the current incident and the recurring risk from external vendors, which is the correct incident-response sequence of contain, eradicate, and prevent.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use Threat Explorer to delete the email from the user's mailbox and create a Safe Links policy to block the malicious URL.

    Why this is correct

    Threat Explorer permits soft-deleting the delivered phishing message from the mailbox, removing the threat, while a Safe Links policy rewrites and blocks the malicious URL at click time for all users, addressing the recurring external-vendor vector. Together they remediate the current incident and prevent recurrence.

  • ✗

    Report the email to Microsoft for analysis and block the sender domain.

    Why it's wrong here

    Reporting to Microsoft and blocking the sender domain does not purge the delivered message from the Finance user's mailbox, leaving the phishing link accessible. Submission is for tuning detections, and domain blocks suit recurring campaigns; here the immediate requirement is removing the specific delivered email.

  • ✗

    Provide security awareness training to the user and mark the incident as resolved.

    Why it's wrong here

    Training alone leaves the delivered phishing email and malicious URL active, so other recipients remain exposed; the incident needs investigation and purge. It is tempting as a low-effort user-focused fix, and would be correct for recurring awareness gaps rather than an active delivered threat.

  • ✗

    Add the sender's domain to the Tenant Allow/Block List as allowed to avoid future false positives.

    Why it's wrong here

    Allow-listing the sender domain suppresses future detections for that domain, directly enabling the phishing campaign to reach Finance again. Tenant Allow/Block List allow entries exist to override false positives on verified-benign senders, not to whitelist a domain implicated in a confirmed delivered phishing alert.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.