Courseiva
easyMultiple ChoiceObjective-mapped

SC-200 Uses Microsoft Defender for Office 365 Practice Question

An organization uses Microsoft Defender for Office 365. A security analyst wants to configure automated investigation and response (AIR) for email threats. When a user reports a phishing email using the Report Message add-in, which automated action can be triggered by an AIR playbook?

⚠ Common exam trap

Many exam-takers confuse automated remediation actions (like soft-delete) with administrative or training-related tasks, leading them to select options that describe manual or non-automated processes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Soft-delete the email from the user's mailbox and other mailboxes that received the same message.

When a user reports a phishing email via the Report Message add-in, the automated investigation and response (AIR) playbook in Microsoft Defender for Office 365 can automatically soft-delete the email from the user's mailbox and from all other mailboxes that received the same message. This action is part of the built-in remediation steps that AIR can take after confirming the threat, leveraging the email entity's hash or message ID to perform tenant-wide removal via the threat protection pipeline.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Trigger a training campaign for the user who reported the email.

    Why it's wrong here

    Triggering a training campaign directly from an automated investigation and response (AIR) playbook is not a supported remediation action in Microsoft Defender for Office 365. Training campaigns are typically launched by security administrators via Attack simulation training or through custom automation after a human review, not automatically as part of an email threat containment playbook. The AIR playbook actions focus on containing and eradicating the threat itself, not on user education, which would be a follow-up step outside the automated response workflow. Moreover, the user who reported the email is likely the victim or observer, not the perpetrator, so targeting them for training without further analysis could be inappropriate and could waste resources.

  • Move the email to the tenant's shared mailbox for review.

    Why it's wrong here

    There is no standard destination called a "tenant's shared mailbox" in Microsoft Defender for Office 365 AIR actions. Automated actions for email threats typically include soft delete, hard delete, move to quarantine, or block URL/file, all of which operate on the message's current location rather than relocating it to a special mailbox. Moving the email to a shared mailbox would not contain the threat, as the email would remain accessible to anyone with access to that mailbox, and it would fail to remove the malicious content from the user's inbox. Additionally, reviewing a reported email is a manual triage step, not an automated remediation action; the AIR playbook is designed to execute containment actions without requiring a shared mailbox for review.

  • Remove the Report Message add-in from Outlook to prevent false reports.

    Why it's wrong here

    Removing the Report Message add-in is a change to the Outlook client configuration, which is outside the scope of Defender for Office 365 AIR playbook actions. AIR actions operate on email messages, files, and URLs through the backend threat protection services, not on user interface components or add-ins. Disabling the add-in would actually hinder the organization's ability to receive user-reported phishing emails, which is a key source of intelligence for the AIR playbook. Furthermore, the add-in is a reporting tool, not a vulnerability, and removing it would not prevent false reports but would reduce visibility into potential threats, undermining the security posture.

  • Soft-delete the email from the user's mailbox and other mailboxes that received the same message.

    Why this is correct

    Soft-deleting the email is a correct and supported AIR action in Microsoft Defender for Office 365 that automatically removes the reported message from the user's mailbox and any other mailboxes that received the same message. This action leverages the message's network message ID or Internet Message ID to identify all instances of the email across the tenant and moves them to the Recoverable Items folder, effectively containing the threat. Once a soft delete is performed, the email is no longer visible to the user but can still be recovered by an administrator within a retention period, balancing security with forensic needs. This is a direct remediation step that aligns with the goal of automatically neutralizing email-borne threats reported by a user.

About these practice questions

This SC-200 question is part of Courseiva's 209-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.