SC-200 - Respond to Security Incidents (37% of the exam) - Section 2.1

Investigate and remediate threats across Microsoft Defender for Office 365, Microsoft Purview, and Microsoft Defender for Cloud workload protections.

Investigate email, collaboration, and data threats using Microsoft Defender for Office 365, and identify compromised entities surfaced by Microsoft Purview. Apply remediation actions for threats detected by Microsoft Defender for Cloud workload protections, choosing the appropriate action for each resource type.

Microsoft Defender for Office 365 with automatic attack disruptioncompromised entities identified by Microsoft PurviewMicrosoft Defender for Cloud workload protectionsremediation actions

Practice question for this objective

Free sampleRespond to Security Incidentsmedium

Microsoft Defender for Office 365 detects a high-confidence business email compromise in which an internal mailbox is sending fraudulent messages to colleagues in real time. The security architect wants automatic attack disruption in Microsoft Defender XDR to contain the compromised mailbox autonomously within minutes, with no analyst initiating the response. Which TWO conditions must both be satisfied so the disruption containment action can be applied to the compromised account? Select TWO.

  • AMicrosoft Defender for Office 365 must be onboarded so its high-confidence email signals feed the Microsoft Defender XDR correlation that drives automatic attack disruption. Correct
  • BAutomated investigation and response must be active in the tenant so the platform has the automation pipeline through which disruption applies its containment action. Correct
  • CA scheduled analytics rule must be authored in Microsoft Sentinel so it raises the incident that automatic attack disruption then waits for and acts upon.
  • DA custom detection rule must be created in Microsoft Defender XDR with the disable-user response action so disruption has an action to invoke.
Automatic attack disruption acting on an Office 365 BEC signal requires Defender for Office 365 onboarded and automated investigation and response active in the tenant. Automatic attack disruption is a built-in Microsoft Defender XDR capability that correlates high-confidence signals and then contains the threat through the automated investigation and response pipeline. For the Office 365 business email compromise signal to drive autonomous containment of the mailbox, Defender for Office 365 must be onboarded so its detections feed the correlation, and automated investigation and response must be active so the containment action can actually be applied.

Why A is correct: Attack disruption acts on correlated cross-workload signals, so the Office 365 workload must be onboarded for its detections to trigger the disruption decision.

Why B is correct: Disruption relies on the automated investigation and response infrastructure to carry out its automatic containment, so AIR must be running for the action to be applied.

Why C is wrong: Attack disruption is built into Microsoft Defender XDR and uses its own high-confidence detections, so it needs no hand-written Sentinel scheduled rule to fire.

Why D is wrong: Disruption supplies its own automatic containment actions and does not depend on a custom detection rule being configured to disable the account.

See more SC-200 practice questions, answers explained.

Exam traps in Respond to Security Incidents

Answers that look right on this material and are not. Each one is a distractor from a different question in the SC-200 bank for this domain.

  • Automated investigation and response (AIR) in Microsoft Defender for Office 365, which opens an investigation on the alert, gathers evidence about the mailbox, and recommends remediation actions once the investigation playbook has finished running.

    Why it is wrong: AIR automates the investigation and proposes remediation, but it works through an evidence-gathering playbook and is not designed to instantly contain a fast-moving, in-progress attack before that investigation completes.

  • Run a full Microsoft Defender Antivirus scan on the affected device to detect and clean any malware the attacker dropped on it.

    Why it is wrong: An antivirus scan is a manual remediation action a responder can trigger, but attack disruption does not run scans as a containment action, so it does not satisfy the requirement.

  • In the secure score recommendations list, which aggregates posture findings across the subscription and assigns each a score impact so the team can prioritise hardening the Kubernetes environment over time.

    Why it is wrong: Secure score recommendations drive posture hardening and prioritisation across resources, but they address general misconfigurations rather than the response steps for a specific live workload protection alert.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.