nerdexam
Microsoft

SC-200 · Question #97

You have a Microsoft 365 tenant that uses Microsoft Exchange Online and Microsoft Defender for Office 365. What should you use to identify whether zero-hour auto purge (ZAP) moved an email message…

The correct answer is A. the Threat Protection Status report in Microsoft Defender for Office 365. To determine if ZAP moved your message, you can use either the Threat Protection Status report or Threat Explorer (and real-time detections). https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/zero-hour-auto- purge?view=o365-worldwide

Submitted by tarun92· Apr 18, 2026Manage threat mitigation using Microsoft Defender XDR

Question

You have a Microsoft 365 tenant that uses Microsoft Exchange Online and Microsoft Defender for Office 365. What should you use to identify whether zero-hour auto purge (ZAP) moved an email message from the mailbox of a user?

Options

  • Athe Threat Protection Status report in Microsoft Defender for Office 365
  • Bthe mailbox audit log in Exchange
  • Cthe Safe Attachments file types report in Microsoft Defender for Office 365
  • Dthe mail flow report in Exchange

How the community answered

(33 responses)
  • A
    94% (31)
  • C
    3% (1)
  • D
    3% (1)

Explanation

To determine if ZAP moved your message, you can use either the Threat Protection Status report or Threat Explorer (and real-time detections). https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/zero-hour-auto- purge?view=o365-worldwide

Topics

#Zero-hour auto purge (ZAP)#Microsoft Defender for Office 365#Threat Protection Status report#Email security reporting

Community Discussion

No community discussion yet for this question.

Full SC-200 Practice