Courseiva

SC-200 Manage a security operations environment Practice Question

Your security team is investigating an incident in Microsoft Defender XDR where a user received multiple phishing emails. The team needs to create an automated response that blocks the sender's email address across all mailboxes in the organization. Which action should you configure in an automated investigation and response (AIR) playbook?

⚠ Common exam trap

Candidates often confuse the scope of Microsoft Defender for Cloud Apps (Option A) with email security controls, mistakenly thinking IP blocking in MDCA can stop email from a specific sender, when in fact email transport blocking is handled exclusively by Defender for Office 365.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add a 'Block sender' action in Microsoft Defender for Office 365.

Blocking a sender's email address across all mailboxes is a native capability of Microsoft Defender for Office 365. The 'Block sender' action in an AIR playbook directly adds the sender to the tenant's block list, which is enforced at the transport layer for all inbound email, effectively preventing any further delivery from that address.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Add a 'Block IP address' action in Microsoft Defender for Cloud Apps.

    Why it's wrong here

    The 'Block IP address' action in Defender for Cloud Apps uses conditional access app control to terminate or restrict user sessions based on source IP, which is a network-layer control for cloud app access, not a mail-flow filter. Since the investigation concerns an email sender's address in Exchange Online, this action would have no effect on message delivery from that sender, making it an incorrect remediation choice.

  • ✗

    Create a custom detection rule in Microsoft Sentinel.

    Why it's wrong here

    A custom detection rule in Microsoft Sentinel can only query and correlate data sources to generate alerts; it cannot natively invoke a block against a sender in Exchange Online. While Sentinel can trigger a playbook via automation rules to call Microsoft 365 Defender APIs for incident response, the detection rule itself is not the blocking mechanism. Thus, creating a rule would help identify the incident but would not directly block the email sender.

  • ✓

    Add a 'Block sender' action in Microsoft Defender for Office 365.

    Why this is correct

    In Microsoft Defender for Office 365, the 'Block sender' action directly adds the sender's email address to the tenant-level block list used by Exchange Online Protection, causing future messages from that address to be rejected during mail flow. This is the appropriate remediation when an email-based threat needs to be stopped at the messaging layer, and it can be executed from the email entity or threat explorer. It is therefore the correct action to block the sender across Exchange Online.

  • ✗

    Deploy a configuration profile in Microsoft Intune.

    Why it's wrong here

    A configuration profile in Microsoft Intune is used to enforce device settings, compliance policies, and application configurations on managed endpoints, and it has no built-in capability to block an email sender in Exchange Online. Intune operates on device management rather than on the mail transport pipeline, so deploying a profile would neither alter EOP filtering nor prevent delivery of messages from the sender's address. This makes Intune an irrelevant tool for sender blocking in this scenario.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.