Courseiva

SC-200 Manage a security operations environment Practice Question

Your organization uses Microsoft Defender XDR. You need to ensure that when a user reports a phishing email in Outlook, it automatically triggers an investigation in Microsoft Defender XDR. What should you configure?

⚠ Common exam trap

Test-takers frequently confuse the native Defender for Office 365 user-reported message settings with a custom Sentinel playbook, overlooking that the question specifically requires automatic investigation in Defender XDR, not a separate SIEM orchestration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable user-reported message settings in Microsoft Defender for Office 365 and configure automated investigation.

Enabling user-reported message settings in Microsoft Defender for Office 365 allows users to report phishing emails directly from Outlook. When combined with automated investigation and response (AIR) policies, this triggers an automatic investigation in Microsoft Defender XDR, leveraging the unified incident and alerting pipeline to analyze the reported message and associated threats.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enable user-reported message settings in Microsoft Defender for Office 365 and configure automated investigation.

    Why this is correct

    Enabling user-reported message settings in Microsoft Defender for Office 365 ingests reports from the Outlook Report button into the system. When configured with automated investigation, each reported message automatically triggers an AIR (Automated Investigation and Response) workflow that runs detonation, threat hunting, and recommended actions. This is the only option that directly connects the user report to a native investigation in Microsoft Defender XDR, matching the requirement.

  • ✗

    Create a playbook in Microsoft Sentinel triggered by a custom connector.

    Why it's wrong here

    While Sentinel playbooks can automate responses, they are not triggered by the Outlook Report button unless you build a custom connector to subscribe to Microsoft Graph APIs for user-reported messages. Even then, the playbook would only run in the Azure Monitor/Sentinel context, requiring manual incident correlation and missing the out-of-the-box email threat detection features of MDO. This approach is far more complex and does not leverage the integrated investigation capabilities of Defender XDR.

  • ✗

    Configure a data loss prevention policy in Microsoft Purview.

    Why it's wrong here

    Data loss prevention policies in Microsoft Purview focus on identifying and protecting sensitive data like credit card numbers and PII in transit and at rest. On a user-reported email, a DLP policy would only assess content against classification rules and apply restrictions such as blocking external sharing or showing a policy tip; it has no mechanism to launch an automated security investigation or analyze phishing threats. Thus it does not satisfy the requirement.

  • ✗

    Set up a session policy in Microsoft Defender for Cloud Apps.

    Why it's wrong here

    Session policies in Microsoft Defender for Cloud Apps are designed for monitoring and controlling user activities in sanctioned and unsanctioned cloud apps using reverse proxy controls, such as controlling downloads or requiring step-up authentication. They operate at the HTTP/S session level and do not ingest Outlook user-reported messages, nor do they perform email-level threat analysis or response. Therefore, they are unrelated to the needed email investigation workflow.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.