Courseiva

SC-200 Manage a security operations environment Practice Question

You are managing Microsoft Defender XDR. The security team reports that some automated investigations are closing prematurely without sufficient evidence. You need to ensure that investigations only close when a minimum confidence level is reached. What should you modify?

⚠ Common exam trap

Watch out — candidates often confuse the 'automation level' setting with 'action center settings' or 'advanced features', leading them to select Option A or B, when in fact the automation level directly controls the confidence threshold for investigation closure.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Adjust the automation level in the Microsoft 365 Defender security settings.

The automation level in Microsoft 365 Defender security settings controls how automated investigations behave, including the confidence level required for actions to be taken or for investigations to close. By adjusting the automation level (e.g., from 'Full – remediate threats automatically' to a higher threshold like 'Semi – require approval for any remediation'), you can ensure that investigations do not close prematurely without sufficient evidence. This setting directly addresses the requirement to enforce a minimum confidence level before closure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Change the action center settings to require manual approval.

    Why it's wrong here

    The action center in Microsoft Defender XDR is designed for managing pending remediation actions, such as approving or rejecting manually initiated or automated responses to alerts. It does not control the confidence threshold that determines when an investigation is automatically resolved, because investigation closure relies on the automation level's built-in trust criteria, not on action approval workflows. Requiring manual approval for actions would delay or block response actions, but it would not alter the criteria for closing an investigation as benign or malicious.

  • ✗

    Modify the tenant-level advanced features in Microsoft Defender XDR.

    Why it's wrong here

    Tenant-level advanced features in Microsoft Defender XDR, such as preview features, tamper protection, or the unified reporting toggle, control the availability of new product capabilities and data collection. They do not expose or modify the confidence level threshold for automatic investigation closure, which is governed by the automation level settings under the Microsoft 365 Defender security settings. Adjusting these advanced features would affect detection coverage or feature enablement, not the decision-making logic for closing incidents or investigations.

  • ✗

    Create a custom detection rule to override default behavior.

    Why it's wrong here

    Custom detection rules in Microsoft Defender XDR allow you to define your own detection logic for specific threats, but they operate at the detection layer and cannot override the platform's built-in investigation closure confidence levels. The automation level is a separate configuration that applies to all automatic investigations and governs when the system is confident enough to close a case without human intervention. Creating a custom rule would add new detections, but it does not change the threshold the automated investigation engine uses to determine if an alert is resolved.

  • ✓

    Adjust the automation level in the Microsoft 365 Defender security settings.

    Why this is correct

    Adjusting the automation level in the Microsoft 365 Defender security settings is the correct action because this setting includes the confidence level required for automatic investigation closure. The automation level can be set to 'Full – Automatically remediate threats,' which allows Defender to act on alerts with a high confidence verdict, or set to 'Semi – require additional confirmation,' which raises the bar for automatic closure. Changing this setting directly controls whether the system closes an investigation without human review, thereby addressing the team's requirement to modify that confidence threshold.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.