SC-200 Manage a security operations environment Practice Question
Your organization uses Microsoft Defender for Office 365. You need to ensure that when a user reports a phishing email, the email is automatically analyzed and remediated. What should you configure?
⚠ Common exam trap
The trap is selecting Safe Links or Safe Attachments because they are phishing-related controls — but the question is about user-reported messages triggering automated analysis and remediation, which is the User Reported Message settings feature.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure User Reported Message settings to use the built-in reporting tool and automated investigation.
Configuring User Reported Message settings in Microsoft 365 Defender to use the built-in reporting tool and enable automated investigation ensures that when a user reports a phishing email, it is routed to Microsoft, analyzed, and remediated automatically (e.g., moved to quarantine, soft-deleted, or blocked for other recipients). This is the purpose-built feature for the scenario. It ties the user report directly into the automated investigation and response (AIR) pipeline.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configure User Reported Message settings to use the built-in reporting tool and automated investigation.
Why this is correct
User Reported Message settings route user-reported phishing into the built-in reporting tool, which feeds automated investigation and response so the message is analysed and remediated without manual triage, meeting the automatic analysis and remediation requirement.
- ✗
Configure Anti-Phish policy to move messages to quarantine.
Why it's wrong here
Anti-phish policies filter inbound mail against impersonation and spoofing signals; they do not process messages a user has already reported, so no automated investigation or remediation is triggered. It is tempting because quarantine removes malicious mail, making this right for blocking inbound phishing rather than handling reported submissions.
- ✗
Enable Safe Attachments policy.
Why it's wrong here
Safe Attachments detonates attachments in a sandbox during mail flow; it does not consume user-reported messages or initiate automated investigation and remediation. It is tempting because detonation catches malicious payloads, so it would be correct when the requirement is attachment scanning rather than the reporting-and-response pipeline.
- ✗
Enable Safe Links policy.
Why it's wrong here
Safe Links rewrites and detonates URLs at click time; it does not ingest user-reported messages or trigger automated investigation and remediation. It is tempting because Safe Links blocks malicious URLs, so it would be correct when the requirement is time-of-click URL protection rather than the user-reported message workflow.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.