AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel
A company uses Microsoft Sentinel as its SIEM. The security team wants to automatically respond to phishing emails detected by Microsoft Defender XDR. They want to create a playbook that, when triggered, will delete the email from all recipients' mailboxes. Which integration should the playbook use?
⚠ Common exam trap
Watch out — candidates often confuse the Microsoft 365 Defender API (which handles detection data) with the Microsoft Graph API (which handles mailbox actions), leading them to select D instead of A.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Graph API
The Microsoft Graph API provides the necessary endpoints to programmatically access and manipulate Exchange Online mail items, including deleting emails from user mailboxes. A Sentinel playbook can use an HTTP trigger with the Graph API to perform the deletion action on behalf of the security team, enabling automated remediation of phishing emails across all recipients.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Microsoft Graph API
Why this is correct
The Microsoft Graph API provides a unified REST endpoint for Microsoft 365 services, including Outlook mail, enabling Sentinel playbooks to execute remediation actions such as soft-deleting or purging malicious emails from a user's mailbox. Since Sentinel's Logic Apps connector supports HTTP requests to Graph API with proper OAuth authentication, it is the appropriate mechanism for mailbox-level threat remediation within an automated incident response workflow. Unlike PowerShell or other APIs, Graph API is directly consumable from a playbook and is designed for cross-service automation.
- ✗
Microsoft Power Automate
Why it's wrong here
Power Automate is the underlying workflow engine that orchestrates Sentinel playbooks, but it is not a distinct API for interacting with Exchange Online mailboxes. The actual data-plane interaction to delete or modify emails is performed through HTTP calls to the Microsoft Graph API, which Power Automate triggers as part of an automated flow. Confusing the orchestration layer with the integration endpoint misidentifies the component that directly manipulates mailbox items.
- ✗
Exchange Online PowerShell
Why it's wrong here
Although Exchange Online PowerShell could technically delete emails (e.g., using Search-Mailbox or New-ComplianceSearchAction), it cannot be invoked directly from a Sentinel playbook because Logic Apps lacks a native PowerShell execution step. The playbook would need an Azure Automation runbook or hybrid worker to run PowerShell, adding complexity and latency compared to a direct Graph API call. Sentinel's native integration and Logic App connector are designed for REST-based APIs, not PowerShell cmdlets.
- ✗
Microsoft 365 Defender API
Why it's wrong here
The Microsoft 365 Defender API is focused on threat intelligence, alert triage, and advanced hunting across endpoints, identities, and email, but it does not expose operations to modify mailbox contents such as deleting or purging messages. Its endpoints return detection and investigation data rather than allowing remediation actions on Exchange Online items. Therefore, it is unsuitable for the specific requirement of removing malicious emails from a user's mailbox.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.