nerdexam
Microsoft

SC-200 · Question #175

You have a Microsoft 365 subscription that uses Microsoft 365 Defender. A remediation action for an automated investigation quarantines a file across multiple devices. You need to mark the file as…

The correct answer is A. From the History tab in the Action center, revert the actions. The Action Center in Microsoft 365 Defender tracks all remediation actions performed by automated investigations (AIR), including file quarantines. To undo a quarantine action - effectively marking the file as safe and releasing it across all affected devices - you go to the…

Submitted by mike_84· Apr 18, 2026Manage threat mitigation using Microsoft Defender XDR

Question

You have a Microsoft 365 subscription that uses Microsoft 365 Defender. A remediation action for an automated investigation quarantines a file across multiple devices. You need to mark the file as safe and remove the file from quarantine on the devices. What should you use in the Microsoft 365 Defender portal?

Options

  • AFrom the History tab in the Action center, revert the actions.
  • BFrom the investigation page, review the AIR processes.
  • CFrom Quarantine from the Review page, modify the rules.
  • DFrom Threat tracker, review the queries.

How the community answered

(23 responses)
  • A
    91% (21)
  • B
    4% (1)
  • C
    4% (1)

Explanation

The Action Center in Microsoft 365 Defender tracks all remediation actions performed by automated investigations (AIR), including file quarantines. To undo a quarantine action - effectively marking the file as safe and releasing it across all affected devices - you go to the History tab in the Action Center and select 'Revert.' This is the correct and efficient method to reverse automated remediation actions at scale.

Topics

#Microsoft 365 Defender#Automated Investigation and Remediation (AIR)#Action center#Quarantine management

Community Discussion

No community discussion yet for this question.

Full SC-200 Practice