Courseiva

SC-200 Manage a security operations environment Practice Question

Which THREE of the following are capabilities of Microsoft Defender XDR's automated investigation and response (AIR) that can be enabled or configured by a security operations analyst? (Choose three.)

⚠ Common exam trap

It's easy for candidates to confuse the capabilities of Microsoft Defender XDR's AIR with those of Microsoft Sentinel's automation rules or other Microsoft 365 compliance features, leading them to select options like modifying DLP policies or creating analytics rules, which are not part of AIR's predefined action set.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Automatically block an email message or attachment.

Microsoft Defender XDR's automated investigation and response (AIR) allows security operations analysts to configure automatic actions such as blocking an email message or attachment. This is a core capability of AIR, which uses playbooks to automatically remediate threats by applying actions like soft-delete or quarantine to malicious emails or attachments based on investigation results.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Automatically block an email message or attachment.

    Why this is correct

    Automated Investigation and Response (AIR) in Microsoft Defender for Office 365 can automatically remediate email-borne threats by soft-deleting or blocking malicious messages and attachments identified during an investigation. This is a core remediation action that stops phishing campaigns and malware delivery directly at the mailbox, without requiring manual intervention.

  • ✓

    Automatically isolate a compromised device.

    Why this is correct

    AIR in Microsoft Defender for Endpoint includes the automatic isolation of a compromised device from the network as a containment step. This action prevents lateral movement and further infection while the investigation proceeds, and it is a standard, predefined remediation action that can be triggered automatically based on suspicious device activity.

  • ✗

    Automatically modify Data Loss Prevention policies.

    Why it's wrong here

    Data Loss Prevention (DLP) policies are configuration-managed in Microsoft Purview, not through Defender XDR automated response actions. AIR’s remediation scope is limited to threat containment, such as blocking indicators, isolating devices, or disabling accounts; it does not alter compliance-related policy settings, so modifying DLP policies is outside its capabilities.

  • ✓

    Automatically suspend a user account.

    Why this is correct

    During an automated investigation, AIR can automatically disable or suspend a user account that is determined to be compromised, thereby stopping further malicious activities such as data exfiltration or unauthorized access. This containment action is performed through Defender XDR's integration with identity protection and is a legitimate remediation step.

  • ✗

    Automatically create new analytics rules based on incident patterns.

    Why it's wrong here

    Creating new analytics rules based on incident patterns is not part of Microsoft Defender XDR's automated investigation and response; analytics rules are authored in Microsoft Sentinel for detection and require manual or scripted creation. AIR only executes remediation actions on existing threats and never generates or modifies detection rules automatically.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SC-200

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which THREE features are available in Microsoft Defender XDR to help automate incident response? (Choose three.)

medium
  • ✓ A.Automated investigation and response (AIR)
  • B.Microsoft Power Automate
  • ✓ C.Advanced hunting
  • ✓ D.Playbooks
  • E.Microsoft Sentinel fusion rule

Why A: Automated investigation and response (AIR) in Microsoft Defender XDR automatically runs playbooks on alerts to investigate and remediate threats without manual intervention. It leverages machine learning and security signals across endpoints, email, and identities to contain malicious activity, such as isolating a compromised device or blocking a malicious file, directly within the incident response workflow.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.