Courseiva
Protect devicesmediumMultiple ChoiceObjective-mapped

MD-102 Protect devices Practice Question

Your company uses Microsoft Defender for Endpoint (Defender XDR). You need to configure an automated investigation and remediation (AIR) rule that automatically quarantines a file when a specific alert is triggered. Which action should you take?

⚠ Common exam trap

Candidates often confuse indicators of compromise (IoC) with automated response rules, mistakenly thinking that adding an IoC for a file will automatically trigger a quarantine action when the file is detected, whereas IoCs only define detection or blocking logic, not conditional alert-triggered remediation workflows.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Create a new automation rule in the Microsoft 365 Defender portal.

Automated investigation and remediation (AIR) rules in Microsoft 365 Defender allow you to define automated actions—such as quarantining a file—when a specific alert is triggered. This is the native mechanism for orchestrating response actions based on alert conditions, directly supporting the requirement to automatically quarantine a file upon alert generation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Add an indicator of compromise for the file.

    Why it's wrong here

    Indicators block or allow files, but do not automate investigation.

  • Configure a device control policy.

    Why it's wrong here

    Device control policies manage peripheral devices, not file responses.

  • Create a new automation rule in the Microsoft 365 Defender portal.

    Why this is correct

    Automation rules define automated actions based on alerts.

  • Create an attack surface reduction rule.

    Why it's wrong here

    ASR rules are for prevention, not automated response to alerts.

Go deeper

Related to this question

About these practice questions

Courseiva writes every MD-102 question from scratch — 942 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.