SC-200 Manage a security operations environment Practice Question
Which THREE features are available in Microsoft Defender XDR to help automate incident response? (Choose three.)
⚠ Common exam trap
Watch out — candidates often confuse Microsoft Power Automate as a native Defender XDR feature for automation, when in fact it is an external tool that requires custom configuration and is not part of Defender XDR's built-in automated investigation and response capabilities.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Automated investigation and response (AIR)
Automated investigation and response (AIR) in Microsoft Defender XDR automatically runs playbooks on alerts to investigate and remediate threats without manual intervention. It leverages machine learning and security signals across endpoints, email, and identities to contain malicious activity, such as isolating a compromised device or blocking a malicious file, directly within the incident response workflow.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Automated investigation and response (AIR)
Why this is correct
Automated investigation and response (AIR) is a built-in capability of Microsoft Defender XDR that self-executes security investigations triggered by alerts, applying algorithms to examine evidence like files, processes, and network communications. It automatically takes corrective actions, such as isolating devices or blocking malicious indicators, and records findings for analysts. AIR reduces alert fatigue by containing threats with minimal human intervention.
- ✗
Microsoft Power Automate
Why it's wrong here
Microsoft Power Automate is a standalone automation service for creating workflow-based integrations across hundreds of applications, including email, SharePoint, and Dataverse. While it can be used to build connectors that interact with Defender XDR APIs, it is not a native feature of the Defender XDR platform itself. For automated security response within Defender XDR, Microsoft provides playbooks based on Azure Logic Apps rather than Power Automate as a core component.
- ✓
Advanced hunting
Why this is correct
Advanced hunting is a query-based hunting tool in Microsoft Defender XDR that lets security analysts use the Kusto Query Language (KQL) to search up to 30 days of raw data across endpoints, Office 365, identities, and cloud apps. It enables proactive threat discovery by allowing custom queries to correlate events and detect anomalies that traditional alerts might miss. Results can be bookmarked, shared, and converted into custom detection rules.
- ✓
Playbooks
Why this is correct
Playbooks in Microsoft Defender XDR are security automation workflows that orchestrate response actions in response to alerts or incidents. They are built on Azure Logic Apps and can run in either an automatically triggered or manually invoked fashion, integrating with hundreds of connectors to execute remediation, enrichment, or notification steps. These playbooks are a core feature of the XDR platform, distinguishing it from generic workflow tools.
- ✗
Microsoft Sentinel fusion rule
Why it's wrong here
The Fusion rule is a detection mechanism specific to Microsoft Sentinel, the enterprise SIEM product, not Microsoft Defender XDR. It correlates multiple low-fidelity signals across cloud and on-premises data sources to create highly accurate incidents based on machine learning techniques. Defender XDR relies on its own correlation and detection engine within the 365 ecosystem rather than Sentinel's Fusion model.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.