Which Microsoft 365 Defender Portals Provide Automated Investigation and Response
Which TWO Microsoft 365 Defender portals provide automated investigation and response capabilities? (Choose two.)
Quick Answer
The answer is Microsoft 365 Defender (security.microsoft.com) and Microsoft Defender for Endpoint. These two portals provide automated investigation and response (AIR) capabilities because they are built on the same underlying security orchestration, automated response, and investigation engine. Microsoft 365 Defender orchestrates AIR across the entire suite—covering email, identity, and cloud apps—while Defender for Endpoint focuses AIR specifically on endpoint devices, automatically remediating threats like malware or suspicious files. On the SC-200 exam, this question tests your ability to distinguish between Microsoft’s security portals: a common trap is confusing Microsoft Sentinel (a SIEM) or Microsoft Purview (compliance) with AIR-capable tools. Remember that AIR is a feature of Defender products, not of SIEM or compliance portals. A simple memory tip: “AIR lives in the Defender family—both the unified portal and the endpoint portal.”
⚠ Common exam trap
Watch out — candidates often confuse Microsoft Sentinel's SOAR capabilities with the built-in AIR features of Microsoft 365 Defender portals, or mistakenly think the Purview compliance portal includes automated incident response.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Defender for Endpoint (security.microsoft.com)
Microsoft Defender for Endpoint (D) and Microsoft 365 Defender (E) both provide automated investigation and response (AIR) capabilities. Defender for Endpoint uses AIR to automatically investigate alerts on endpoints and take remediation actions, while Microsoft 365 Defender orchestrates AIR across email, identity, endpoints, and cloud apps. These portals are accessed via security.microsoft.com and offer built-in playbooks for automated response.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Purview compliance portal
Why it's wrong here
Purview is for compliance, not automated investigation and response.
- ✗
Microsoft Sentinel (portal.azure.com)
Why it's wrong here
Sentinel is a SIEM, not the portal for automated investigation and response.
- ✗
Microsoft Intune admin center
Why it's wrong here
Intune is for device management, not automated investigation.
- ✓
Microsoft Defender for Endpoint (security.microsoft.com)
Why this is correct
Defender for Endpoint has automated investigation and response for endpoint threats.
- ✓
Microsoft 365 Defender (security.microsoft.com)
Why this is correct
Microsoft 365 Defender includes automated investigation and response for incidents.
Go deeper
Related to this question
About these practice questions
One of 209 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SC-200
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which TWO tools in Microsoft Defender XDR provide automated investigation and response capabilities?
medium- ✓ A.Microsoft Defender for Endpoint
- ✓ B.Microsoft Defender for Office 365
- C.Microsoft Defender for Identity
- D.Microsoft Defender for Cloud Apps
- E.Microsoft Defender for Cloud
Why A: Automated investigation and response (AIR) is available in Defender for Office 365 and Defender for Endpoint. Defender for Identity and Defender for Cloud Apps have some automation but not full AIR. Defender for Cloud is separate.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.