Courseiva

AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel

A company uses Microsoft Sentinel as its SIEM. The security team wants to automatically respond to phishing emails detected by Microsoft Defender XDR. They want to create a playbook that, when triggered, will delete the email from all recipients' mailboxes. Which integration should the playbook use?

⚠ Common exam trap

Watch out — candidates often confuse the Microsoft 365 Defender API (which handles detection data) with the Microsoft Graph API (which handles mailbox actions), leading them to select D instead of A.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Graph API

The Microsoft Graph API provides the necessary endpoints to programmatically access and manipulate Exchange Online mail items, including deleting emails from user mailboxes. A Sentinel playbook can use an HTTP trigger with the Graph API to perform the deletion action on behalf of the security team, enabling automated remediation of phishing emails across all recipients.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Microsoft Graph API

    Why this is correct

    The Microsoft Graph API provides a unified REST endpoint for Microsoft 365 services, including Outlook mail, enabling Sentinel playbooks to execute remediation actions such as soft-deleting or purging malicious emails from a user's mailbox. Since Sentinel's Logic Apps connector supports HTTP requests to Graph API with proper OAuth authentication, it is the appropriate mechanism for mailbox-level threat remediation within an automated incident response workflow. Unlike PowerShell or other APIs, Graph API is directly consumable from a playbook and is designed for cross-service automation.

  • ✗

    Microsoft Power Automate

    Why it's wrong here

    Power Automate is the underlying workflow engine that orchestrates Sentinel playbooks, but it is not a distinct API for interacting with Exchange Online mailboxes. The actual data-plane interaction to delete or modify emails is performed through HTTP calls to the Microsoft Graph API, which Power Automate triggers as part of an automated flow. Confusing the orchestration layer with the integration endpoint misidentifies the component that directly manipulates mailbox items.

  • ✗

    Exchange Online PowerShell

    Why it's wrong here

    Although Exchange Online PowerShell could technically delete emails (e.g., using Search-Mailbox or New-ComplianceSearchAction), it cannot be invoked directly from a Sentinel playbook because Logic Apps lacks a native PowerShell execution step. The playbook would need an Azure Automation runbook or hybrid worker to run PowerShell, adding complexity and latency compared to a direct Graph API call. Sentinel's native integration and Logic App connector are designed for REST-based APIs, not PowerShell cmdlets.

  • ✗

    Microsoft 365 Defender API

    Why it's wrong here

    The Microsoft 365 Defender API is focused on threat intelligence, alert triage, and advanced hunting across endpoints, identities, and email, but it does not expose operations to modify mailbox contents such as deleting or purging messages. Its endpoints return detection and investigation data rather than allowing remediation actions on Exchange Online items. Therefore, it is unsuitable for the specific requirement of removing malicious emails from a user's mailbox.

About these practice questions

Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.