Courseiva
Respond to security incidentseasyMultiple SelectObjective-mapped

Which Microsoft 365 Defender Portals Provide Automated Investigation and Response

Which TWO Microsoft 365 Defender portals provide automated investigation and response capabilities? (Choose two.)

Quick Answer

The answer is Microsoft 365 Defender (security.microsoft.com) and Microsoft Defender for Endpoint. These two portals provide automated investigation and response (AIR) capabilities because they are built on the same underlying security orchestration, automated response, and investigation engine. Microsoft 365 Defender orchestrates AIR across the entire suite—covering email, identity, and cloud apps—while Defender for Endpoint focuses AIR specifically on endpoint devices, automatically remediating threats like malware or suspicious files. On the SC-200 exam, this question tests your ability to distinguish between Microsoft’s security portals: a common trap is confusing Microsoft Sentinel (a SIEM) or Microsoft Purview (compliance) with AIR-capable tools. Remember that AIR is a feature of Defender products, not of SIEM or compliance portals. A simple memory tip: “AIR lives in the Defender family—both the unified portal and the endpoint portal.”

⚠ Common exam trap

Watch out — candidates often confuse Microsoft Sentinel's SOAR capabilities with the built-in AIR features of Microsoft 365 Defender portals, or mistakenly think the Purview compliance portal includes automated incident response.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Microsoft Defender for Endpoint (security.microsoft.com)

Microsoft Defender for Endpoint (D) and Microsoft 365 Defender (E) both provide automated investigation and response (AIR) capabilities. Defender for Endpoint uses AIR to automatically investigate alerts on endpoints and take remediation actions, while Microsoft 365 Defender orchestrates AIR across email, identity, endpoints, and cloud apps. These portals are accessed via security.microsoft.com and offer built-in playbooks for automated response.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Microsoft Purview compliance portal

    Why it's wrong here

    Purview is for compliance, not automated investigation and response.

  • Microsoft Sentinel (portal.azure.com)

    Why it's wrong here

    Sentinel is a SIEM, not the portal for automated investigation and response.

  • Microsoft Intune admin center

    Why it's wrong here

    Intune is for device management, not automated investigation.

  • Microsoft Defender for Endpoint (security.microsoft.com)

    Why this is correct

    Defender for Endpoint has automated investigation and response for endpoint threats.

  • Microsoft 365 Defender (security.microsoft.com)

    Why this is correct

    Microsoft 365 Defender includes automated investigation and response for incidents.

About these practice questions

One of 209 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SC-200

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which TWO tools in Microsoft Defender XDR provide automated investigation and response capabilities?

medium
  • A.Microsoft Defender for Endpoint
  • B.Microsoft Defender for Office 365
  • C.Microsoft Defender for Identity
  • D.Microsoft Defender for Cloud Apps
  • E.Microsoft Defender for Cloud

Why A: Automated investigation and response (AIR) is available in Defender for Office 365 and Defender for Endpoint. Defender for Identity and Defender for Cloud Apps have some automation but not full AIR. Defender for Cloud is separate.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.