SC-200 Manage a security operations environment Practice Question
Your SOC team uses Microsoft Defender XDR. You want to ensure that all incidents are automatically classified and determined by the built-in AI before any manual review. What should you configure?
⚠ Common exam trap
Many exam-takers confuse the AI-driven incident classification in Defender XDR with automation rules in Microsoft Sentinel, which are for response actions, not for the built-in AI classification and determination of incidents.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable the incident summarization and classification feature in Microsoft Defender XDR.
Microsoft Defender XDR includes a built-in AI-driven incident summarization and classification feature that automatically assigns a classification (e.g., true positive, false positive) and determination (e.g., malicious, clean) to each incident before manual review. This feature leverages machine learning models trained on Microsoft's global threat intelligence to reduce alert fatigue and streamline SOC workflows.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a custom detection rule in Microsoft Defender XDR.
Why it's wrong here
Custom detection rules in Microsoft Defender XDR are KQL-based queries that generate alerts when a specific pattern or behavior is observed; they do not have any AI classification or determination capability. While they are useful for detecting niche threats, each alert they produce still requires manual triage and is not automatically classified as a true or false positive. Therefore, creating such a rule would not satisfy the objective of using Defender's native AI-driven incident classification.
- ✓
Enable the incident summarization and classification feature in Microsoft Defender XDR.
Why this is correct
The incident summarization and classification feature in Microsoft Defender XDR is a built-in AI capability that automatically analyzes the alert and incident evidence, generates a natural-language summary, and assigns a classification (e.g., true positive, false positive, informational) and determination to each incident. Enabling this feature meets the stated objective because it activates the platform's native machine learning reasoning to pre-classify incidents before human review, significantly reducing analyst workload.
- ✗
Enable automation rules in Microsoft Sentinel to classify incidents.
Why it's wrong here
Enabling automation rules in Microsoft Sentinel would classify incidents within Sentinel, not by activating the native built-in AI classification and determination features of Microsoft Defender XDR as required. The question specifically targets Defender XDR's inherent AI capabilities for pre-manual review. This option is tempting because Sentinel automation rules are indeed used to classify and enrich incidents, and perform automated actions based on custom logic, making them ideal for bespoke incident management workflows once incidents are ingested into Sentinel.
- ✗
Configure a workbook in Microsoft Sentinel to analyze incidents.
Why it's wrong here
Configuring a workbook in Microsoft Sentinel creates an interactive visualization dashboard powered by KQL queries; workbooks are exclusively for displaying and exploring log data and have no AI classification or automated decisioning logic. Although workbooks can highlight incident trends, they neither classify incidents nor modify incident properties, so they cannot accomplish the goal of enabling automatic AI-driven incident classification in Defender XDR. This option is also outside the Defender XDR feature set, since workbooks belong to Sentinel.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 209 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.