SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
A security analyst at Fabrikam, Inc. is reviewing alerts in the Microsoft 365 Defender portal. The analyst needs to understand the function of the 'Automated investigation and response' (AIR) capability in Microsoft Defender for Office 365. What is the primary purpose of AIR?
⚠ Common exam trap
Candidates often confuse AIR with email traffic monitoring or DLP enforcement, when AIR is specifically about automated investigation and remediation of threats.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To automatically investigate alerts and take remediation actions, such as soft-deleting malicious emails.
Automated investigation and response (AIR) in Microsoft Defender for Office 365 automatically investigates alerts and takes remediation actions, such as soft-deleting malicious emails, blocking senders, and removing malicious attachments. It helps security teams respond to threats quickly and consistently without manual intervention for every alert.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
To automatically block all incoming email messages from external domains.
Why it's wrong here
AIR does not block all external email messages. Such a blanket block would disrupt business communications and is not the purpose of AIR. Instead, AIR focuses on investigating and remediating threats that have been detected, not on implementing a global block. Blocking all external email is a manual configuration that would be overly restrictive and is not a feature of AIR.
- ✗
To provide a real-time dashboard of all email traffic in the organization.
Why it's wrong here
AIR does not provide a real-time dashboard of email traffic. That functionality is available through reports and Explorer in the Microsoft 365 Defender portal. AIR is an automated investigation and remediation engine, not a monitoring or reporting tool. While it may generate investigation results, its primary purpose is to act on threats, not to display traffic metrics.
- ✗
To enforce data loss prevention policies for email attachments.
Why it's wrong here
Data loss prevention (DLP) policies are configured separately, typically in Microsoft Purview. AIR does not enforce DLP policies. While both are security capabilities, AIR focuses on threat investigation and remediation, whereas DLP focuses on preventing sensitive data from being shared inappropriately. They are distinct features and should not be confused.
- ✓
To automatically investigate alerts and take remediation actions, such as soft-deleting malicious emails.
Why this is correct
AIR in Microsoft Defender for Office 365 automatically investigates alerts triggered by suspicious emails, attachments, or links. It can then take remediation actions, such as soft-deleting malicious messages from user mailboxes, blocking malicious senders, and removing malicious attachments. This reduces the burden on security teams and accelerates response to threats.
Go deeper
Related to this question
Learn chapter
Microsoft Purview Compliance Portal
Key term
Microsoft Defender for Office 365
Microsoft Defender for Office 365 is a cloud-based email and collaboration security service that protects organizations against malicious threats like phishing, malware, and spam in email messages and Office 365 apps.
Key term
Anti-phishing policy
An anti-phishing policy is a set of rules and technical controls that organizations use to detect, block, and respond to email or message-based attacks that trick users into revealing sensitive information.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,279 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.