Courseiva
easyMultiple Choice

Automated Actions in Microsoft Defender for Office 365 AIR

An organization uses Microsoft Defender for Office 365. The security team wants to automatically investigate and respond to user-reported phishing emails. Which feature should they enable to automate this process?

⚠ Common exam trap

Watch out — candidates often confuse 'Attack simulation training' (a proactive training tool) with the automated response capability, or they think 'Threat Explorer' or 'Campaign views' can automate responses, when in fact those are manual investigation and visualization tools, not automated response engines.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Automated investigation and response (AIR)

Automated investigation and response (AIR) in Microsoft Defender for Office 365 automatically triggers a playbook when a user reports a phishing email via the Report Message or Report Phishing add-in. It collects the email, analyzes it using threat intelligence and machine learning, and takes remediation actions such as soft-deleting the message or blocking the sender, all without manual intervention.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Attack simulation training

    Why it's wrong here

    Attack simulation training is a security-awareness feature that delivers simulated phishing emails and payloads to teach users how to recognize and report real attacks. It does not ingest or analyze actual user-submitted emails, nor does it execute any remediation workflows. Therefore, while it improves the human layer, it provides no automated response to a genuine threat reported by a user.

  • ✓

    Automated investigation and response (AIR)

    Why this is correct

    Automated investigation and response (AIR) in Microsoft Defender for Office 365 enables playbook-driven automation that triages alerts generated from user-reported messages. When a user reports a suspicious email, AIR can trigger automated actions such as soft-deleting the message, disabling a malicious URL, quarantining files, and consolidating related alerts into a single investigation. This is the only option that both automatically analyzes and remediates real threats originating from user-reported emails.

  • ✗

    Campaign views

    Why it's wrong here

    Campaign views is an analytical aggregation in Threat Explorer that groups related attacks into distinct campaigns to reveal attacker behavior, scale, and techniques. It offers deep visibility into campaign geometry and attack flow, but it is purely a visualization and reporting layer—it does not initiate or manage any automated investigative or remediation steps. Consequently, it cannot fulfill a requirement for automated response to user-reported messages.

  • ✗

    Threat Explorer

    Why it's wrong here

    Threat Explorer is a manual threat-hunting tool that allows security analysts to query email metadata, message traces, and detections with sophisticated filters and custom date ranges. While it supports administrative remediation actions like hard-deleting or purging messages, those actions require human selection and do not occur automatically when a user reports an email. Its role is investigative and reactive, not automated response.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.