SC-200 Manage a security operations environment Practice Question
Which THREE of the following are capabilities of Microsoft Defender XDR's automated investigation and response (AIR) that can be enabled or configured by a security operations analyst? (Choose three.)
⚠ Common exam trap
It's easy for candidates to confuse the capabilities of Microsoft Defender XDR's AIR with those of Microsoft Sentinel's automation rules or other Microsoft 365 compliance features, leading them to select options like modifying DLP policies or creating analytics rules, which are not part of AIR's predefined action set.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Automatically block an email message or attachment.
Microsoft Defender XDR's automated investigation and response (AIR) allows security operations analysts to configure automatic actions such as blocking an email message or attachment. This is a core capability of AIR, which uses playbooks to automatically remediate threats by applying actions like soft-delete or quarantine to malicious emails or attachments based on investigation results.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Automatically block an email message or attachment.
Why this is correct
Automated Investigation and Response (AIR) in Microsoft Defender for Office 365 can automatically remediate email-borne threats by soft-deleting or blocking malicious messages and attachments identified during an investigation. This is a core remediation action that stops phishing campaigns and malware delivery directly at the mailbox, without requiring manual intervention.
- ✓
Automatically isolate a compromised device.
Why this is correct
AIR in Microsoft Defender for Endpoint includes the automatic isolation of a compromised device from the network as a containment step. This action prevents lateral movement and further infection while the investigation proceeds, and it is a standard, predefined remediation action that can be triggered automatically based on suspicious device activity.
- ✗
Automatically modify Data Loss Prevention policies.
Why it's wrong here
Data Loss Prevention (DLP) policies are configuration-managed in Microsoft Purview, not through Defender XDR automated response actions. AIR’s remediation scope is limited to threat containment, such as blocking indicators, isolating devices, or disabling accounts; it does not alter compliance-related policy settings, so modifying DLP policies is outside its capabilities.
- ✓
Automatically suspend a user account.
Why this is correct
During an automated investigation, AIR can automatically disable or suspend a user account that is determined to be compromised, thereby stopping further malicious activities such as data exfiltration or unauthorized access. This containment action is performed through Defender XDR's integration with identity protection and is a legitimate remediation step.
- ✗
Automatically create new analytics rules based on incident patterns.
Why it's wrong here
Creating new analytics rules based on incident patterns is not part of Microsoft Defender XDR's automated investigation and response; analytics rules are authored in Microsoft Sentinel for detection and require manual or scripted creation. AIR only executes remediation actions on existing threats and never generates or modifies detection rules automatically.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SC-200
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which THREE features are available in Microsoft Defender XDR to help automate incident response? (Choose three.)
medium- ✓ A.Automated investigation and response (AIR)
- B.Microsoft Power Automate
- ✓ C.Advanced hunting
- ✓ D.Playbooks
- E.Microsoft Sentinel fusion rule
Why A: Automated investigation and response (AIR) in Microsoft Defender XDR automatically runs playbooks on alerts to investigate and remediate threats without manual intervention. It leverages machine learning and security signals across endpoints, email, and identities to contain malicious activity, such as isolating a compromised device or blocking a malicious file, directly within the incident response workflow.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.