SC-200 Practice Question 3748

Exam: SC-200
Domain: Respond to security incidents
Difficulty: medium
You are reviewing a phishing alert in Microsoft Defender for Office 365. An executive was duped into receiving a malicious email with an external phishing link. Which tool allows a security analyst to search for and soft-delete that message across all other employee inboxes?

Answer Options

A
Threat Explorer (Explorer) in the Defender portal
B
Event Viewer on the domain controller
C
SharePoint Online storage management page
D
Azure Cost Management budgeting alerts

Correct Answer

A: Threat Explorer (Explorer) in the Defender portal

Explanation

Threat Explorer (Explorer) in the Defender portal enables analysts to query email messages by subject or sender and initiate "Take action" to move or delete messages from all inboxes.