mediumMultiple ChoiceObjective-mapped
SC-200 Practice Question: In Microsoft 365 Defender, a security analyst…
In Microsoft 365 Defender, a security analyst reviews an automated investigation that found a potentially unwanted application on multiple devices. The analyst wants to manually approve the suggested remediation action of uninstalling the application. Where should the analyst go?
⚠ Common exam trap
A common mix-up: candidates confuse the Incidents page or Alerts queue as the place to approve remediation actions, not realizing that the Action center is the sole interface for managing pending remediation actions from automated investigations.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The Action center
The Action center in Microsoft 365 Defender is the centralized location where security analysts can view and manually approve or reject remediation actions that were suggested by automated investigations, such as uninstalling a potentially unwanted application. This is the correct place because the Action center consolidates all pending and completed actions across devices, allowing the analyst to take direct manual intervention on the recommended remediation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The Action center
Why this is correct
The Action center is the centralized console in Microsoft 365 Defender where all pending and completed remediation actions — such as file quarantine, device isolation, and email deletion — are listed, regardless of their originating automated investigation or manual response. Analysts must use this hub to review and either approve or reject each pending action before it is executed, and the center also preserves a full history for audit and investigation purposes. Because it is specifically designed to aggregate these actionable tasks from across Microsoft Defender for Endpoint, Office 365, and Identity, it is the only place that meets the analyst's need to review remediation actions.
- ✗
The Incidents page
Why it's wrong here
The Incidents page aggregates alerts and evidence into a single attack narrative, displaying the full investigation graph with impacted devices, users, and mailboxes. While you can view the actions that were taken within a specific incident and even launch new response actions from its timeline or 'Actions' tab, its purpose is to provide incident-level context rather than to act as a cross-tenant queue of pending approvals. It does not give a consolidated view of every remediation action awaiting approval across all incidents, which is why it does not satisfy the need to review pending actions.
- ✗
The Alerts queue
Why it's wrong here
The Alerts queue lists individual security alerts across the Microsoft 365 Defender services, each representing a specific detection with severity, status, and associated entities. Alerts may trigger automated investigations and responses, but the queue itself is for triaging alerts and investigating them, not for managing the resulting remediation actions. The approval of actions such as isolating a device or blocking a file is handled in the Action center, whereas the alert queue only shows the alert-level data and links to an investigation, so it does not contain the list of pending remediation actions.
- ✗
The Device inventory
Why it's wrong here
The Device inventory displays all onboarded devices in Microsoft Defender for Endpoint, showing metadata like OS, risk level, exposure level, and sensor health but no remediation action statuses. Its primary role is to let analysts manage device lifecycle and understand each machine's security posture, not to serve as an approval workflow for action tasks. Even if a device has a pending isolation or scan action, the inventory entry only reflects the device state; the action itself is tracked and approved in the Action center, so this page cannot fulfill the review requirement.
Go deeper
Related to this question
About these practice questions
One of 209 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.