Microsoft Security Operations Analyst Associate SC-200 Practice Question

Several employees report a suspicious email that was delivered four days ago and is still sitting in multiple mailboxes. Your company has Microsoft 365 E5 licenses with Microsoft Defender for Office 365 Plan 2. You must immediately remove the message from every mailbox but still keep a copy available to Security Operations Center (SOC) investigators for eDiscovery. Which action should you take in the Microsoft Defender portal?

  • Add the sender's domain to the Tenant Allow/Block List to block future messages from the sender.

  • Use Threat Explorer to locate the message and run the Soft delete action across all affected mailboxes.

  • Enable or update a Safe Links policy that rewrites the URL contained in the email.

  • Trigger an Automated Investigation and Response (AIR) playbook for phishing from the Email entity page.

Microsoft Security Operations Analyst Associate SC-200
Manage incident response
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot