Courseiva
mediumMultiple Choice

SC-200 Practice Question: A security analyst in Microsoft 365 Defender…

A security analyst in Microsoft 365 Defender needs to review all actions that were automatically taken by an investigation (e.g., isolating a device, deleting a file) that occurred during an incident. Where should the analyst find this list of executed actions?

⚠ Common exam trap

Candidates often confuse the Incidents page (which shows the overall story) with the Action center (which is the specific repository for executed actions), leading them to select the Incidents page instead of the correct Action center.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Action center

The Action center in Microsoft 365 Defender is the centralized location that records all manual and automated response actions taken during investigations, such as device isolation, file deletion, or process termination. This includes actions automatically executed by automated investigation and response (AIR) playbooks during an incident. The analyst can filter the Action center by 'Automated' to see only those actions taken without manual intervention.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Action center

    Why this is correct

    Action center is the centralized console in Microsoft 365 Defender that consolidates all automated and manual remediation actions taken during investigations. It provides a unified queue with detailed status (e.g., Pending, Completed, Failed), execution history, approval workflows for pending actions, and results for each operation such as quarantining a file, isolating a device, or blocking a sender. This makes it the authoritative location for reviewing both the actions themselves and their outcomes.

  • ✗

    Hunting queries

    Why it's wrong here

    Advanced hunting in Microsoft 365 Defender is a KQL-based query tool used to proactively search raw telemetry tables (e.g., DeviceProcessEvents, EmailEvents) for indicators of compromise and anomalous behavior. It is designed for threat discovery and pattern analysis, not for operational review of remediation actions. Although hunting queries can reveal suspicious activity, they do not expose the lifecycle, approval status, or execution results of actions that were already taken during investigations.

  • ✗

    Incidents page

    Why it's wrong here

    The Incidents page in Microsoft 365 Defender provides an aggregated ticket-level view of a security incident, showing related alerts, affected assets, the attack story timeline, and overall severity. It focuses on the incident narrative and evidence, but it does not enumerate the detailed remediation actions that were performed as part of the investigation. While you can see that an incident was 'Contained' or 'Resolved,' the specific actions (e.g., 'Stop and quarantine a file') with their success/failure metadata are only fully documented in the Action center.

  • ✗

    Alerts page

    Why it's wrong here

    The Alerts page lists discrete security alerts, such as 'Malicious PowerShell process' or 'Suspicious inbound email,' with metadata including title, severity, and status. It represents detection signals, not the remediation steps that were executed in response. An alert may trigger an automated investigation that performs multiple actions, but the Alerts page only reflects the alert's own state and does not show the parameters, device-level results, or whether actions were approved or reverted. This operational detail is exclusively maintained in the Action center.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SC-200

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. In Microsoft 365 Defender, what is the primary function of the Action center?

easy
  • A.Manage user roles and permissions for the security portal.
  • ✓ B.View and manage pending and completed remediation actions from automated investigations.
  • C.Create custom detection rules using advanced hunting queries.
  • D.Manage threat intelligence feeds and indicators.

Why B: The Action center in Microsoft 365 Defender is the centralized console for tracking and managing remediation actions generated by automated investigations. It consolidates both pending actions (requiring approval) and completed actions (e.g., quarantining a file, blocking an IP) across Defender for Endpoint, Office 365, Identity, and Cloud Apps, ensuring security teams can review and approve or reject responses without switching contexts.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.