easyMultiple Choice
Automated Actions in Microsoft Defender for Office 365 AIR
An organization uses Microsoft Defender for Office 365. The security team wants to automatically investigate and respond to user-reported phishing emails. Which feature should they enable to automate this process?
⚠ Common exam trap
Watch out — candidates often confuse 'Attack simulation training' (a proactive training tool) with the automated response capability, or they think 'Threat Explorer' or 'Campaign views' can automate responses, when in fact those are manual investigation and visualization tools, not automated response engines.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Automated investigation and response (AIR)
Automated investigation and response (AIR) in Microsoft Defender for Office 365 automatically triggers a playbook when a user reports a phishing email via the Report Message or Report Phishing add-in. It collects the email, analyzes it using threat intelligence and machine learning, and takes remediation actions such as soft-deleting the message or blocking the sender, all without manual intervention.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Attack simulation training
Why it's wrong here
Attack simulation training is a security-awareness feature that delivers simulated phishing emails and payloads to teach users how to recognize and report real attacks. It does not ingest or analyze actual user-submitted emails, nor does it execute any remediation workflows. Therefore, while it improves the human layer, it provides no automated response to a genuine threat reported by a user.
- ✓
Automated investigation and response (AIR)
Why this is correct
Automated investigation and response (AIR) in Microsoft Defender for Office 365 enables playbook-driven automation that triages alerts generated from user-reported messages. When a user reports a suspicious email, AIR can trigger automated actions such as soft-deleting the message, disabling a malicious URL, quarantining files, and consolidating related alerts into a single investigation. This is the only option that both automatically analyzes and remediates real threats originating from user-reported emails.
- ✗
Campaign views
Why it's wrong here
Campaign views is an analytical aggregation in Threat Explorer that groups related attacks into distinct campaigns to reveal attacker behavior, scale, and techniques. It offers deep visibility into campaign geometry and attack flow, but it is purely a visualization and reporting layer—it does not initiate or manage any automated investigative or remediation steps. Consequently, it cannot fulfill a requirement for automated response to user-reported messages.
- ✗
Threat Explorer
Why it's wrong here
Threat Explorer is a manual threat-hunting tool that allows security analysts to query email metadata, message traces, and detections with sophisticated filters and custom date ranges. While it supports administrative remediation actions like hard-deleting or purging messages, those actions require human selection and do not occur automatically when a user reports an email. Its role is investigative and reactive, not automated response.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.