Courseiva

SC-200 Manage a security operations environment Practice Question

Your organization uses Microsoft Defender for Endpoint. You need to ensure that when a malware alert is generated, an automated investigation is triggered. What should you configure?

⚠ Common exam trap

Many exam-takers confuse the Action center (which handles post-investigation remediation actions) with the automated investigation configuration itself, leading them to select Option A, when in fact the trigger is controlled by the automation level settings in the Microsoft 365 Defender portal under 'Automated investigation and remediation'.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable automated investigation and remediation in the Microsoft 365 Defender portal.

Enabling automated investigation and remediation in the Microsoft 365 Defender portal is the specific configuration that triggers an automated investigation when a malware alert is generated by Microsoft Defender for Endpoint. This feature allows the security operations team to define the automation level (e.g., full, semi, or no automation) for alerts, ensuring that when a malware alert fires, the system automatically initiates an investigation to contain and remediate the threat without manual intervention.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure the Action center settings.

    Why it's wrong here

    The Action center is a centralized queue for pending manual remediation actions and investigation results; its settings govern user notifications and action approvals, not the automatic initiation of investigation workflows. Automated investigations are toggled via the automated investigation and remediation settings in the Microsoft 365 Defender portal. Therefore, changing Action center settings does not enable the system to automatically trigger investigations on alerts.

  • ✗

    Create custom indicators of compromise (IOCs).

    Why it's wrong here

    Custom IOCs, such as file hashes or domains, define threat actors' artifacts for detection and alerting, but they only add to the detection rule set; they do not configure the platform's behavior to automatically open an investigation when an alert fires. Automated investigation execution is governed by the 'Automated investigation and remediation' control, not by the presence of indicators. Thus, creating IOCs would not cause automatic investigations to be triggered.

  • ✗

    Use threat analytics to trigger investigations.

    Why it's wrong here

    Threat analytics is a reporting and threat intelligence module that provides context about active threats, including mitigations and affected products; it does not expose a setting to initiate automated investigation workflows. Automated investigations are a separate feature that runs when alerts are generated and when the automated investigation and remediation capability is enabled. Hence, using threat analytics cannot directly trigger investigations on alerts.

  • ✓

    Enable automated investigation and remediation in the Microsoft 365 Defender portal.

    Why this is correct

    In Microsoft 365 Defender (now Microsoft Defender XDR), the 'Automated investigation and remediation' feature is the switch that allows alerts to automatically run investigation and remediation actions. When this setting is enabled, Defender for Endpoint automatically starts an investigation for qualifying alerts, providing the required automation. This configuration, not other controls like IOCs or the Action center, is the correct way to enable automatic investigation triggers.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.