Courseiva

SC-200 Manage a security operations environment Practice Question

Your company uses Microsoft Defender for Office 365. You want to automatically take action on malicious emails that bypass the filter. What should you configure?

⚠ Common exam trap

Many exam-takers confuse pre-delivery protection policies (like anti-phishing or Safe Attachments) with post-delivery automated response capabilities, assuming any security policy can automatically act on bypassed emails, but only AIR provides the automated investigation and remediation workflow for threats that have already evaded initial filters.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure automated investigation and response (AIR) policies.

Automated investigation and response (AIR) policies in Microsoft Defender for Office 365 are specifically designed to automatically take action on malicious emails that bypass initial filters. AIR uses playbooks to investigate threats and automatically remediate, such as deleting or moving emails, without manual intervention. This directly addresses the requirement to automatically act on bypassed malicious emails.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable anti-phishing policy.

    Why it's wrong here

    An anti-phishing policy in Defender for Office 365 is primarily a preventative control that applies impersonation protection, spoof intelligence, and mailbox intelligence at the point of delivery. It can quarantine suspicious messages based on policy verdicts, but it does not orchestrate an automated response when a campaign is detected after delivery. This policy lacks the investigative and remediation workflows needed to soft-delete or purge already-sent malicious messages across mailboxes.

  • ✗

    Enable Safe Attachments policy.

    Why it's wrong here

    A Safe Attachments policy focuses on time-of-delivery protection by routing messages through detonation chambers to identify malicious attachments. While it can block a suspicious message or replace an unsafe attachment, it does not automatically investigate related email, URLs, or sender patterns after the fact. This option is about scanning at ingress, not automated post-breach remediation, so it cannot satisfy the requirement to remediate threats already in the environment.

  • ✗

    Create a transport rule in Exchange.

    Why it's wrong here

    Creating a transport rule in Exchange is a manual, static configuration that applies conditional actions such as redirecting, blocking, or modifying messages during mail flow. It does not trigger dynamic threat investigation or use evidence from alerts to determine the scope of a campaign, and it would not automatically remediate emails that have already been delivered. Transport rules also lack the built-in playbooks and response actions available in Defender for Office 365 AIR.

  • ✓

    Configure automated investigation and response (AIR) policies.

    Why this is correct

    Automated investigation and response (AIR) policies in Defender for Office 365 use built-in playbooks triggered by security alerts to automatically investigate potentially malicious emails and take remediation actions. These actions include soft-deleting messages, quarantining suspicious content, blocking sender IPs or URLs, and disabling compromised accounts based on the investigation verdict. AIR is specifically designed for post-delivery response, making it the correct choice to automatically remediate a confirmed threat.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.