Courseiva

SC-200 Manage a security operations environment Practice Question

You are responsible for Microsoft Defender for Identity. The security team reports that some high-confidence alerts are not triggering any automated response. You need to automate the response for these alerts. What should you configure?

⚠ Common exam trap

Many candidates confuse Microsoft Sentinel (a SIEM/SOAR) with the native automated investigation and response capabilities within Microsoft Defender XDR, assuming that any automation must go through Sentinel, when in fact Defender XDR provides built-in AIR for its own alerts including Identity alerts.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

In Microsoft Defender XDR, configure automated investigation and response for Identity alerts.

Microsoft Defender for Identity alerts are natively integrated into Microsoft Defender XDR (formerly Microsoft 365 Defender), which provides automated investigation and response (AIR) capabilities. By configuring AIR for Identity alerts in Defender XDR, you can automatically trigger remediation actions such as suspending compromised accounts or blocking suspicious activities without additional scripting or third-party tools.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use Microsoft Intune to trigger a script on domain controllers when an alert fires.

    Why it's wrong here

    Microsoft Intune is a unified endpoint management platform that enrolls and manages devices such as laptops, tablets, and mobile devices. Domain controllers are generally not enrolled in Intune, and Intune has no native trigger mechanism tied directly to Defender for Identity alerts. Intune scripts are device configuration remediation tasks, not identity-threat response actions, so using Intune to respond to identity alerts is architecturally incorrect.

  • ✗

    Create an automation rule in Microsoft Sentinel to respond to Identity alerts.

    Why it's wrong here

    Microsoft Sentinel automation rules operate on Sentinel incidents and analytics rules, not on the alert pipeline of Defender for Identity. While MDI can be connected as a data source into Sentinel, that integration produces incidents in Sentinel, and only then can automation rules or playbooks run. This indirect workflow is not the native, immediate response path for Defender for Identity; the platform-level AIR in Defender XDR is the correct mechanism.

  • ✓

    In Microsoft Defender XDR, configure automated investigation and response for Identity alerts.

    Why this is correct

    Defender XDR provides automated investigation and response (AIR) for identity alerts generated by Defender for Identity. This feature automatically investigates suspicious identity activity, such as compromised account usage or lateral movement, and can contain or remediate threats by disabling accounts, resetting passwords, or blocking sign-ins. Enabling AIR for identity alerts in the Defender XDR portal ensures that alerts are handled through the security incident lifecycle rather than requiring separate device management or compliance tooling.

  • ✗

    Configure Microsoft Purview compliance policies to respond to Identity alerts.

    Why it's wrong here

    Microsoft Purview is a data governance, compliance, and risk management solution that handles data lifecycle, retention, eDiscovery, and insider risk policies. It does not ingest or act on Defender for Identity alerts, and its compliance policies are not designed for incident response or attack mitigation. Using Purview to respond to identity alerts would place response actions outside the security operations workflow and ignore the integrated AIR capabilities of Defender XDR.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.