SC-200 - Respond to Security Incidents - Section 2.1

Investigate and remediate threats across Microsoft Defender for Office 365, Microsoft Purview, and Microsoft Defender for Cloud workload protections.

Investigate email, collaboration, and data threats using Microsoft Defender for Office 365, and identify compromised entities surfaced by Microsoft Purview. Apply remediation actions for threats detected by Microsoft Defender for Cloud workload protections, choosing the appropriate action for each resource type.

Microsoft Defender for Office 365 with automatic attack disruptioncompromised entities identified by Microsoft PurviewMicrosoft Defender for Cloud workload protectionsremediation actions

Practice question for this objective

Free sampleRespond to Security Incidentsmedium

Microsoft Defender for Office 365 detects a high-confidence business email compromise in which an internal mailbox is sending fraudulent messages to colleagues in real time. The security architect wants automatic attack disruption in Microsoft Defender XDR to contain the compromised mailbox autonomously within minutes, with no analyst initiating the response. Which TWO conditions must both be satisfied so the disruption containment action can be applied to the compromised account? Select TWO.

  • AMicrosoft Defender for Office 365 must be onboarded so its high-confidence email signals feed the Microsoft Defender XDR correlation that drives automatic attack disruption. Correct
  • BAutomated investigation and response must be active in the tenant so the platform has the automation pipeline through which disruption applies its containment action. Correct
  • CA scheduled analytics rule must be authored in Microsoft Sentinel so it raises the incident that automatic attack disruption then waits for and acts upon.
  • DA custom detection rule must be created in Microsoft Defender XDR with the disable-user response action so disruption has an action to invoke.
Automatic attack disruption acting on an Office 365 BEC signal requires Defender for Office 365 onboarded and automated investigation and response active in the tenant. Automatic attack disruption is a built-in Microsoft Defender XDR capability that correlates high-confidence signals and then contains the threat through the automated investigation and response pipeline. For the Office 365 business email compromise signal to drive autonomous containment of the mailbox, Defender for Office 365 must be onboarded so its detections feed the correlation, and automated investigation and response must be active so the containment action can actually be applied.

Why A is correct: Attack disruption acts on correlated cross-workload signals, so the Office 365 workload must be onboarded for its detections to trigger the disruption decision.

Why B is correct: Disruption relies on the automated investigation and response infrastructure to carry out its automatic containment, so AIR must be running for the action to be applied.

Why C is wrong: Attack disruption is built into Microsoft Defender XDR and uses its own high-confidence detections, so it needs no hand-written Sentinel scheduled rule to fire.

Why D is wrong: Disruption supplies its own automatic containment actions and does not depend on a custom detection rule being configured to disable the account.

See more SC-200 practice questions, answers explained.

More in this domain

Back to all Respond to Security Incidents objectives, or the SC-200 cert hub.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.