mediumMultiple Choice
SC-200 Practice Question: A security analyst in Microsoft 365 Defender…
A security analyst in Microsoft 365 Defender needs to review all actions that were automatically taken by an investigation (e.g., isolating a device, deleting a file) that occurred during an incident. Where should the analyst find this list of executed actions?
⚠ Common exam trap
Candidates often confuse the Incidents page (which shows the overall story) with the Action center (which is the specific repository for executed actions), leading them to select the Incidents page instead of the correct Action center.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Action center
The Action center in Microsoft 365 Defender is the centralized location that records all manual and automated response actions taken during investigations, such as device isolation, file deletion, or process termination. This includes actions automatically executed by automated investigation and response (AIR) playbooks during an incident. The analyst can filter the Action center by 'Automated' to see only those actions taken without manual intervention.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Action center
Why this is correct
Action center is the centralized console in Microsoft 365 Defender that consolidates all automated and manual remediation actions taken during investigations. It provides a unified queue with detailed status (e.g., Pending, Completed, Failed), execution history, approval workflows for pending actions, and results for each operation such as quarantining a file, isolating a device, or blocking a sender. This makes it the authoritative location for reviewing both the actions themselves and their outcomes.
- ✗
Hunting queries
Why it's wrong here
Advanced hunting in Microsoft 365 Defender is a KQL-based query tool used to proactively search raw telemetry tables (e.g., DeviceProcessEvents, EmailEvents) for indicators of compromise and anomalous behavior. It is designed for threat discovery and pattern analysis, not for operational review of remediation actions. Although hunting queries can reveal suspicious activity, they do not expose the lifecycle, approval status, or execution results of actions that were already taken during investigations.
- ✗
Incidents page
Why it's wrong here
The Incidents page in Microsoft 365 Defender provides an aggregated ticket-level view of a security incident, showing related alerts, affected assets, the attack story timeline, and overall severity. It focuses on the incident narrative and evidence, but it does not enumerate the detailed remediation actions that were performed as part of the investigation. While you can see that an incident was 'Contained' or 'Resolved,' the specific actions (e.g., 'Stop and quarantine a file') with their success/failure metadata are only fully documented in the Action center.
- ✗
Alerts page
Why it's wrong here
The Alerts page lists discrete security alerts, such as 'Malicious PowerShell process' or 'Suspicious inbound email,' with metadata including title, severity, and status. It represents detection signals, not the remediation steps that were executed in response. An alert may trigger an automated investigation that performs multiple actions, but the Alerts page only reflects the alert's own state and does not show the parameters, device-level results, or whether actions were approved or reverted. This operational detail is exclusively maintained in the Action center.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SC-200
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. In Microsoft 365 Defender, what is the primary function of the Action center?
easy- A.Manage user roles and permissions for the security portal.
- ✓ B.View and manage pending and completed remediation actions from automated investigations.
- C.Create custom detection rules using advanced hunting queries.
- D.Manage threat intelligence feeds and indicators.
Why B: The Action center in Microsoft 365 Defender is the centralized console for tracking and managing remediation actions generated by automated investigations. It consolidates both pending actions (requiring approval) and completed actions (e.g., quarantining a file, blocking an IP) across Defender for Endpoint, Office 365, Identity, and Cloud Apps, ensuring security teams can review and approve or reject responses without switching contexts.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.