nerdexam
Microsoft

MS-900 · Question #450

A company is using Microsoft 365 Defender. The company requires the ability to filter alerts and recommend actions that a security team can approve or reject. You need to identify the component that f

The correct answer is C. automated investigation and response. The automated investigation and response (AIR) feature within Microsoft 365 Defender is designed to automatically investigate alerts, filter them, and propose remediation actions that security teams can approve or reject.

Submitted by neha2k· Mar 5, 2026Describe security, compliance, privacy, and trust in Microsoft 365

Question

A company is using Microsoft 365 Defender. The company requires the ability to filter alerts and recommend actions that a security team can approve or reject. You need to identify the component that filters and recommends actions. Which component should you use?

Options

  • ACloud Access Security Broker
  • Bthreat trackers
  • Cautomated investigation and response
  • Dadvanced hunting
  • Ethreat analytics

How the community answered

(31 responses)
  • A
    10% (3)
  • C
    71% (22)
  • D
    16% (5)
  • E
    3% (1)

Why each option

The automated investigation and response (AIR) feature within Microsoft 365 Defender is designed to automatically investigate alerts, filter them, and propose remediation actions that security teams can approve or reject.

ACloud Access Security Broker

A Cloud Access Security Broker (CASB) primarily provides visibility, control, and protection for cloud applications, rather than filtering M365 Defender alerts and recommending specific approve/reject actions.

Bthreat trackers

"Threat trackers" is not a standard, identifiable component within Microsoft 365 Defender that performs the specified function of filtering alerts and recommending approve/reject actions.

Cautomated investigation and responseCorrect

Microsoft 365 Defender's automated investigation and response (AIR) capabilities are specifically designed to automatically investigate alerts, filter out noise, and generate remediation actions. These recommended actions are then presented to security analysts for approval or rejection, directly meeting the requirement.

Dadvanced hunting

Advanced hunting is a proactive, query-based threat hunting tool used to search for threats and indicators, not to automatically filter existing alerts and recommend actions for approval/rejection.

Ethreat analytics

Threat analytics provides expert-backed threat intelligence and reports on active threats, but it does not filter specific alerts and recommend approve/reject actions for remediation within the security team's workflow.

Concept tested: Microsoft 365 Defender Automated Investigation and Response

Source: https://learn.microsoft.com/en-us/microsoft-365/security/defender/m365d-autoir?view=o365-worldwide

Topics

#Microsoft Defender XDR#automated investigation and response#security alerts#threat remediation

Community Discussion

No community discussion yet for this question.

Full MS-900 Practice