Microsoft 365 Administrator Expert MS-102 Practice Question
While triaging several "Phish delivered" alerts in Microsoft 365 Defender, a security analyst confirms that the messages contain a credential-harvesting link. The analyst wants Microsoft Defender for Office 365 to automatically investigate the alert, determine every mailbox that received the message, and generate remediation actions such as soft-deleting the email. From the alert page, which action should the analyst choose to begin this automated investigation?
Selecting Initiate automated investigation (also labeled Trigger automated investigation in some interfaces) launches an Automated Investigation and Response (AIR) playbook. The playbook analyzes delivery telemetry, correlates related entities, and produces pending remediation actions-such as soft-deleting or quarantining the malicious email across all located mailboxes-based on policy settings. The other actions do not start AIR: Create incident only groups alerts for triage, Resolve alert merely changes the alert state, and Suppress similar alerts stops future alerts of the same type without performing any investigation or remediation.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Automated Investigation and Response (AIR) in Microsoft Defender for Office 365?
Open an interactive chat with Bash
How does Initiating Automated Investigation differ from creating an incident in Microsoft Defender for Office 365?
Open an interactive chat with Bash
What happens when choosing 'Suppress similar alerts' in Microsoft Defender for Office 365?
Open an interactive chat with Bash
Microsoft 365 Administrator Expert MS-102
Manage security and threats by using Microsoft Defender XDR
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .