Microsoft 365 Administrator Expert MS-102 Practice Question
While investigating a phishing campaign, you locate a newly delivered message in Microsoft 365 Defender's Threat Explorer. The tenant is licensed for Microsoft Defender for Office 365 Plan 2 and Automated Investigation and Response (AIR) is enabled. You must remove the message from every affected mailbox and have Microsoft 365 automatically analyze related senders, URLs, and attachments so that similar threats are blocked in the future with the least manual effort. Which action should you take first in Threat Explorer?
Create a transport (mail flow) rule that deletes messages containing the malicious URL.
Add the sender's domain to the Exchange Online Protection blocked senders list.
Submit the message to Microsoft for analysis in the Submissions portal.
Select the message and choose "Trigger automated investigation".
Selecting "Trigger automated investigation" in Threat Explorer immediately launches an AIR playbook against the chosen message. The playbook analyzes the email, any correlated artifacts (such as URLs, sender infrastructure, and attachments), and automatically takes remediation steps-including purging or quarantining related messages-subject to admin approval settings. Other options either require additional configuration (creating a transport rule), only block future messages without touching already-delivered mail (adding a domain to blocked senders), or simply submit the sample to Microsoft without initiating tenant-level remediation (submitting for analysis). Therefore, starting an automated investigation best meets both removal and prevention requirements with minimal effort.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Threat Explorer in Microsoft 365 Defender?
Open an interactive chat with Bash
What is Automated Investigation and Response (AIR) in Microsoft Defender for Office 365?
Open an interactive chat with Bash
How does 'Trigger automated investigation' work in Threat Explorer?
Open an interactive chat with Bash
Microsoft 365 Administrator Expert MS-102
Manage security and threats by using Microsoft Defender XDR
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .