Courseiva

SC-200 Manage a security operations environment Practice Question

Your organization uses Microsoft Defender for Office 365. You need to create a custom alert that triggers when users receive external emails with attachments from untrusted domains. What should you configure?

⚠ Common exam trap

Candidates often confuse alert policies (which detect and notify) with mail flow rules (which enforce actions like blocking or quarantining), leading them to choose Option B when the question specifically asks for creating a custom alert.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an alert policy in Microsoft 365 Defender.

A custom alert policy in Microsoft 365 Defender can be configured to detect when users receive external emails with attachments from untrusted domains. This leverages the built-in threat detection capabilities of Defender for Office 365, allowing you to define conditions such as sender domain reputation and attachment presence, and trigger an alert when the criteria are met.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create an alert policy in Microsoft 365 Defender.

    Why this is correct

    Creating an alert policy in Microsoft 365 Defender is correct because alert policies are specifically designed to monitor email activities and generate alerts when conditions are met. For instance, a policy can detect user-reported phishing, suspected malware, or unusual email forwarding patterns, producing an alert that appears in the Defender portal. These alerts can then be assigned severity, include custom notifications, and integrate with incident response queues.

  • ✗

    Create a mail flow rule in Exchange admin center.

    Why it's wrong here

    A mail flow rule created in the Exchange admin center is incorrect because these rules, also called transport rules, evaluate and act on messages during routing, with actions like rejecting, redirecting, or adding a BCC. While you could approximate a notification by sending a copy to a mailbox, that is not a true security alert and does not appear in Microsoft 365 Defender's alert queue. Furthermore, mail flow rules cannot trigger the alerting pipeline or be associated with response actions like automated investigation.

  • ✗

    Set up a conditional access policy in Microsoft Entra ID.

    Why it's wrong here

    A conditional access policy in Microsoft Entra ID is wrong for this scenario because conditional access governs authentication and session behavior, such as requiring MFA or blocking access from untrusted devices, based on user, group, location, or application signals. It does not inspect the content of email messages nor does it generate alerts about email-borne threats. Therefore, while it can reduce risk by preventing access, it is not a tool for creating email event alerts that a security operations team would investigate.

  • ✗

    Configure a data sensitivity label in Microsoft Purview.

    Why it's wrong here

    Configuring a data sensitivity label in Microsoft Purview is not suitable because sensitivity labels are designed to classify and protect the data itself, applying encryption, watermarking, or restricting permissions when attached to emails and documents. Labels do not evaluate email events or propagate security alerts; they act as metadata that can influence downstream processes like data loss prevention. Even if a label appears on a malicious email, it will not create an alert in Microsoft 365 Defender, so this is not a replacement for a dedicated alert policy.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.