SC-200 Manage a security operations environment Practice Question
Your organization uses Microsoft Defender for Office 365. You need to ensure that when a user reports a phishing email via the built-in Outlook add-in, an automated investigation is triggered in Microsoft 365 Defender. What should you configure?
⚠ Common exam trap
Test-takers frequently confuse the configuration for automated investigation triggers with anti-phishing or safe links policies, not realizing that the user-reported message settings are the specific control that bridges user reporting to automated incident response.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable user-reported message settings in the Microsoft 365 Defender portal.
Enabling user-reported message settings in the Microsoft 365 Defender portal allows messages reported via the built-in Outlook add-in to automatically trigger an automated investigation (AIR) in Microsoft 365 Defender. This configuration ties the user reporting action directly to the incident response workflow, enabling the system to analyze the reported email and initiate remediation steps without manual intervention.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Define a safe links policy.
Why it's wrong here
Safe Links is a time-of-click URL protection feature that scans and rewrites links in email messages and Office documents to prevent malicious access. It operates at the message flow level and does not ingest user-reported submissions, nor does it have a mechanism to launch an automated investigation when a user reports a message. Therefore, configuring a Safe Links policy would not meet the requirement to trigger automated investigations.
- ✓
Enable user-reported message settings in the Microsoft 365 Defender portal.
Why this is correct
User-reported message settings in the Microsoft 365 Defender portal control how messages reported by end users via the Report Message or Report Phishing add-ins are processed. By enabling these settings and selecting the appropriate option, you can route reported messages to Microsoft or to a custom mailbox, and—critically—you can choose to automatically trigger an investigation and response (AIR) in Defender for Office 365 on those reports. This is the only setting among the options that directly ties user reporting to automated investigation.
- ✗
Configure an anti-phishing policy.
Why it's wrong here
An anti-phishing policy in Defender for Office 365 provides protection against phishing attempts through impersonation protection, spoof intelligence, and mailbox intelligence actions applied to inbound messages. It does not contain any configuration that processes user-reported messages or starts an automated investigation in response to such reports. Automated investigations rely on user-reported message settings, not on the anti-phishing policy's delivery or detection actions.
- ✗
Set up a safe attachments policy.
Why it's wrong here
Safe Attachments policies protect against malicious attachments by routing messages to a detonation chamber and then taking action based on the detonation verdict. While this scans email attachments, it is a proactive content-based control that operates independently of user feedback. It cannot be configured to launch an automated investigation when a user reports a message, because that workflow is governed by user-reported message settings.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SC-200
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Your organization uses Microsoft Defender XDR. You need to ensure that when a user reports a phishing email in Outlook, it automatically triggers an investigation in Microsoft Defender XDR. What should you configure?
medium- ✓ A.Enable user-reported message settings in Microsoft Defender for Office 365 and configure automated investigation.
- B.Create a playbook in Microsoft Sentinel triggered by a custom connector.
- C.Configure a data loss prevention policy in Microsoft Purview.
- D.Set up a session policy in Microsoft Defender for Cloud Apps.
Why A: Enabling user-reported message settings in Microsoft Defender for Office 365 allows users to report phishing emails directly from Outlook. When combined with automated investigation and response (AIR) policies, this triggers an automatic investigation in Microsoft Defender XDR, leveraging the unified incident and alerting pipeline to analyze the reported message and associated threats.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.