Courseiva
Manage a security operations environmentmediumMultiple ChoiceObjective-mapped

SC-200 Manage a security operations environment Practice Question

Your SOC team uses Microsoft Defender XDR. You want to ensure that all incidents are automatically classified and determined by the built-in AI before any manual review. What should you configure?

⚠ Common exam trap

Many exam-takers confuse the AI-driven incident classification in Defender XDR with automation rules in Microsoft Sentinel, which are for response actions, not for the built-in AI classification and determination of incidents.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Enable the incident summarization and classification feature in Microsoft Defender XDR.

Microsoft Defender XDR includes a built-in AI-driven incident summarization and classification feature that automatically assigns a classification (e.g., true positive, false positive) and determination (e.g., malicious, clean) to each incident before manual review. This feature leverages machine learning models trained on Microsoft's global threat intelligence to reduce alert fatigue and streamline SOC workflows.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Create a custom detection rule in Microsoft Defender XDR.

    Why it's wrong here

    Custom detection rules in Microsoft Defender XDR are KQL-based queries that generate alerts when a specific pattern or behavior is observed; they do not have any AI classification or determination capability. While they are useful for detecting niche threats, each alert they produce still requires manual triage and is not automatically classified as a true or false positive. Therefore, creating such a rule would not satisfy the objective of using Defender's native AI-driven incident classification.

  • Enable the incident summarization and classification feature in Microsoft Defender XDR.

    Why this is correct

    The incident summarization and classification feature in Microsoft Defender XDR is a built-in AI capability that automatically analyzes the alert and incident evidence, generates a natural-language summary, and assigns a classification (e.g., true positive, false positive, informational) and determination to each incident. Enabling this feature meets the stated objective because it activates the platform's native machine learning reasoning to pre-classify incidents before human review, significantly reducing analyst workload.

  • Enable automation rules in Microsoft Sentinel to classify incidents.

    Why it's wrong here

    Enabling automation rules in Microsoft Sentinel would classify incidents within Sentinel, not by activating the native built-in AI classification and determination features of Microsoft Defender XDR as required. The question specifically targets Defender XDR's inherent AI capabilities for pre-manual review. This option is tempting because Sentinel automation rules are indeed used to classify and enrich incidents, and perform automated actions based on custom logic, making them ideal for bespoke incident management workflows once incidents are ingested into Sentinel.

  • Configure a workbook in Microsoft Sentinel to analyze incidents.

    Why it's wrong here

    Configuring a workbook in Microsoft Sentinel creates an interactive visualization dashboard powered by KQL queries; workbooks are exclusively for displaying and exploring log data and have no AI classification or automated decisioning logic. Although workbooks can highlight incident trends, they neither classify incidents nor modify incident properties, so they cannot accomplish the goal of enabling automatic AI-driven incident classification in Defender XDR. This option is also outside the Defender XDR feature set, since workbooks belong to Sentinel.

About these practice questions

Courseiva writes every SC-200 question from scratch — 209 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.