Courseiva
mediumMultiple ChoiceObjective-mapped

SC-200 Practice Question: In Microsoft 365 Defender, a security analyst…

In Microsoft 365 Defender, a security analyst reviews an automated investigation that found a potentially unwanted application on multiple devices. The analyst wants to manually approve the suggested remediation action of uninstalling the application. Where should the analyst go?

⚠ Common exam trap

A common mix-up: candidates confuse the Incidents page or Alerts queue as the place to approve remediation actions, not realizing that the Action center is the sole interface for managing pending remediation actions from automated investigations.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The Action center

The Action center in Microsoft 365 Defender is the centralized location where security analysts can view and manually approve or reject remediation actions that were suggested by automated investigations, such as uninstalling a potentially unwanted application. This is the correct place because the Action center consolidates all pending and completed actions across devices, allowing the analyst to take direct manual intervention on the recommended remediation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The Action center

    Why this is correct

    The Action center is the centralized console in Microsoft 365 Defender where all pending and completed remediation actions — such as file quarantine, device isolation, and email deletion — are listed, regardless of their originating automated investigation or manual response. Analysts must use this hub to review and either approve or reject each pending action before it is executed, and the center also preserves a full history for audit and investigation purposes. Because it is specifically designed to aggregate these actionable tasks from across Microsoft Defender for Endpoint, Office 365, and Identity, it is the only place that meets the analyst's need to review remediation actions.

  • The Incidents page

    Why it's wrong here

    The Incidents page aggregates alerts and evidence into a single attack narrative, displaying the full investigation graph with impacted devices, users, and mailboxes. While you can view the actions that were taken within a specific incident and even launch new response actions from its timeline or 'Actions' tab, its purpose is to provide incident-level context rather than to act as a cross-tenant queue of pending approvals. It does not give a consolidated view of every remediation action awaiting approval across all incidents, which is why it does not satisfy the need to review pending actions.

  • The Alerts queue

    Why it's wrong here

    The Alerts queue lists individual security alerts across the Microsoft 365 Defender services, each representing a specific detection with severity, status, and associated entities. Alerts may trigger automated investigations and responses, but the queue itself is for triaging alerts and investigating them, not for managing the resulting remediation actions. The approval of actions such as isolating a device or blocking a file is handled in the Action center, whereas the alert queue only shows the alert-level data and links to an investigation, so it does not contain the list of pending remediation actions.

  • The Device inventory

    Why it's wrong here

    The Device inventory displays all onboarded devices in Microsoft Defender for Endpoint, showing metadata like OS, risk level, exposure level, and sensor health but no remediation action statuses. Its primary role is to let analysts manage device lifecycle and understand each machine's security posture, not to serve as an approval workflow for action tasks. Even if a device has a pending isolation or scan action, the inventory entry only reflects the device state; the action itself is tracked and approved in the Action center, so this page cannot fulfill the review requirement.

About these practice questions

One of 209 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.