Courseiva

SC-200 Manage a security operations environment Practice Question

Your organization uses Microsoft Defender for Office 365. You want to automatically isolate a user's mailbox if a high-confidence phishing email is detected. Which Microsoft Sentinel automation should you use?

⚠ Common exam trap

A common mix-up: candidates confuse data connectors (which only ingest data) with automated response capabilities, or assume that analytics rules can directly execute remediation actions, when in fact only playbooks (or automation rules that invoke playbooks) can perform such actions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a playbook that uses the Microsoft Graph API to apply a mailbox litigation hold or block access.

Microsoft Sentinel playbooks, built on Azure Logic Apps, can use the Microsoft Graph API to perform automated remediation actions like applying a mailbox litigation hold or blocking user access. This enables automatic isolation of a user's mailbox when a high-confidence phishing email is detected, which is a key incident response capability in Defender for Office 365.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure a workbook to display the alert and manually isolate the mailbox.

    Why it's wrong here

    Workbooks are Azure Monitor-based interactive dashboards that visualize Sentinel data for analysis, but they cannot execute remediation steps. Even though a workbook might surface an alert about a suspicious mailbox, applying a litigation hold or blocking access would require a manual step such as running a PowerShell cmdlet or Graph API call. This option lacks any automation, so it cannot serve as the automated response capability required for incident remediation.

  • ✓

    Create a playbook that uses the Microsoft Graph API to apply a mailbox litigation hold or block access.

    Why this is correct

    Playbooks in Microsoft Sentinel are Azure Logic Apps workflows that automate response actions when triggered by an incident or alert. By calling the Microsoft Graph API, a playbook can programmatically apply a litigation hold to preserve mailbox content or block user access through conditional access policies. This provides a reliable, repeatable SOAR solution that integrates with Office 365 without requiring manual intervention.

  • ✗

    Enable the Office 365 connector and configure automatic response in the data connector.

    Why it's wrong here

    The Office 365 data connector is designed solely to ingest audit and activity logs into Sentinel for visibility and detection; it does not expose any settings for automated response actions. While enabling the connector is necessary for log collection, any response automation must be implemented separately using automation rules that invoke playbooks. Misunderstanding the connector's ingest-only role would leave the environment vulnerable because no isolation action would ever execute automatically.

  • ✗

    Create a scheduled analytics rule that isolates the mailbox when triggered.

    Why it's wrong here

    Scheduled analytics rules are KQL-based detection queries that generate alerts or incidents on a recurring schedule, but they have no native mechanism to execute response actions like mailbox isolation. To act on a rule's output, you must attach an automation rule that triggers a playbook, which then performs the remediation via Graph API. Creating just a scheduled rule would only produce an alert; it would not isolate the mailbox, making this option functionally incomplete.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.