MD-102 Protect devices Practice Question
A company uses Microsoft Defender for Endpoint. They want to automatically remediate threats on endpoints using automated investigation and response. They also need to ensure that the remediation actions are approved by the security team before execution. Which configuration should they use?
⚠ Common exam trap
Watch out — candidates often confuse 'Full - remediate threats automatically' (which implies automatic execution) with the ability to require approval, not realizing that 'Approval mode' is a separate toggle that overrides automatic execution even when the remediation level is set to 'Full.'
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable automated investigation and set 'Approval mode' for remediation actions.
Microsoft Defender for Endpoint's automated investigation and response (AIR) capabilities include an 'Approval mode' setting that requires security team approval before any remediation action (e.g., isolating a device, removing a file) is executed. This satisfies the requirement for automatic threat detection and investigation while maintaining human oversight over remediation actions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disable automated investigation and use manual response only.
Why it's wrong here
This does not meet the requirement for automated investigation.
- ✗
Enable automated investigation and allow all actions automatically.
Why it's wrong here
This does not require approval.
- ✗
Enable automated investigation and set remediation level to 'Full - remediate threats automatically'.
Why it's wrong here
This does not require approval.
- ✓
Enable automated investigation and set 'Approval mode' for remediation actions.
Why this is correct
Approval mode requires security team approval before executing remediation.
Go deeper
Related to this question
Learn chapter
Introduction to Endpoint Management in Microsoft 365
Key term
Microsoft Defender for Endpoint
Microsoft Defender for Endpoint is a cloud-delivered enterprise-grade security platform that protects devices, servers, and networks from advanced cyber threats by combining antivirus, endpoint detection and response, and automated investigation and remediation.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
This MD-102 question is part of Courseiva's 942-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.