Microsoft Security Operations Analyst Associate SC-200 Practice Question
Several employees report a suspicious email that was delivered four days ago and is still sitting in multiple mailboxes. Your company has Microsoft 365 E5 licenses with Microsoft Defender for Office 365 Plan 2. You must immediately remove the message from every mailbox but still keep a copy available to Security Operations Center (SOC) investigators for eDiscovery. Which action should you take in the Microsoft Defender portal?
Add the sender's domain to the Tenant Allow/Block List to block future messages from the sender.
Use Threat Explorer to locate the message and run the Soft delete action across all affected mailboxes.
Enable or update a Safe Links policy that rewrites the URL contained in the email.
Trigger an Automated Investigation and Response (AIR) playbook for phishing from the Email entity page.
In Microsoft Defender for Office 365, Threat Explorer (or Real-time detections) lets you locate a specific message and take remediation actions across all mailboxes. Choosing the Soft delete action removes the mail item from users' visible folders and places it in the Recoverable Items folder, so end users can no longer access it while investigators can still retrieve the message through eDiscovery. An Automated Investigation or Safe Links policy does not retroactively delete already-delivered mail, and blocking the sender prevents future messages but leaves the existing message in place.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Threat Explorer in Microsoft Defender for Office 365?
Open an interactive chat with Bash
What is the Soft delete action in Threat Explorer?
Open an interactive chat with Bash
What is eDiscovery and how does it work with Microsoft 365?
Open an interactive chat with Bash
Microsoft Security Operations Analyst Associate SC-200
Manage incident response
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .