Courseiva

SC-200 Manage a security operations environment Practice Question

Which THREE components are required to enable automated investigation and response (AIR) in Microsoft Defender XDR for alerts from Microsoft Defender for Identity?

⚠ Common exam trap

Many candidates confuse the need for a SIEM (Sentinel) or custom automation (playbooks) with the built-in, native AIR capabilities of Microsoft Defender XDR, leading them to select unnecessary components like A or E.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Automated investigation and response enabled in Microsoft Defender XDR.

Automated investigation and response (AIR) must be explicitly enabled in Microsoft Defender XDR to allow the platform to automatically respond to alerts. Without this setting enabled, even if other components are in place, the system will not trigger automated actions for Defender for Identity alerts.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Microsoft Sentinel workspace configured to ingest Defender for Identity alerts.

    Why it's wrong here

    A Microsoft Sentinel workspace that ingests Defender for Identity alerts is not required because Sentinel is an optional SIEM layer, not part of the Microsoft Defender XDR automated investigation and response stack. Defender for Identity sends signals directly to Defender XDR through its native data connector; Sentinel would only consume copies of those alerts for additional querying or custom analytics. The built-in AIR engine operates entirely within Defender XDR, so no Sentinel ingestion is needed to enable automatic investigation or response.

  • ✓

    Automated investigation and response enabled in Microsoft Defender XDR.

    Why this is correct

    Automated investigation and response must be enabled in Microsoft Defender XDR as the central control that orchestrates the investigation workflow when a Defender for Identity alert is triggered. When enabled, Defender XDR automatically opens an incident, runs investigation steps across identity signals, and executes response actions such as disabling compromised accounts or enforcing password resets. This toggle distinguishes autonomous remediation from manual threat hunting; without it, alerts are merely displayed and no automated actions occur.

  • ✓

    A Microsoft 365 E5 license.

    Why this is correct

    A Microsoft 365 E5 license is a hard prerequisite because it includes both Microsoft Defender for Identity and the Defender XDR automated investigation and response capabilities required for this scenario. Defender for Identity is also available as a standalone SKU, but the integrated identity-based alerting and automatic remediation workflows are part of the E5 feature set. Licensing determines whether you can onboard the sensors and access the AIR dashboards that drive this solution.

  • ✓

    Microsoft Defender for Identity onboarded and connected to Microsoft Defender XDR.

    Why this is correct

    Microsoft Defender for Identity must be onboarded and connected to Microsoft Defender XDR so that its domain-controller sensors and identity signals are reachable by the AIR engine. Onboarding requires installing the analyzer (sensor) on domain controllers, configuring the service tenant, and allowing the data feed to flow into the Defender XDR portal. Only alerts that have reached Defender XDR can be evaluated by AIR; a disconnected or partially onboarded Defender for Identity instance leaves the automation blind to identity threats.

  • ✗

    A custom playbook in Microsoft Sentinel.

    Why it's wrong here

    A custom playbook in Microsoft Sentinel is not required—or even involved—because Defender XDR's built-in AIR uses its own predefined playbooks (response actions) that run inside the unified platform. Sentinel custom playbooks are Azure Logic Apps used for orchestrating external security processes, but they are not a prerequisite for native automated investigation and response. Treating Sentinel playbooks as a requirement conflates the SIEM automation model with the out-of-the-box AIR engine, which operates independently of Sentinel.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.