Courseiva
Protect devices →mediumMultiple Choice

MD-102 Protect devices Practice Question

Your company uses Microsoft Defender for Endpoint (Defender XDR). You need to configure an automated investigation and remediation (AIR) rule that automatically quarantines a file when a specific alert is triggered. Which action should you take?

⚠ Common exam trap

Candidates often confuse indicators of compromise (IoC) with automated response rules, mistakenly thinking that adding an IoC for a file will automatically trigger a quarantine action when the file is detected, whereas IoCs only define detection or blocking logic, not conditional alert-triggered remediation workflows.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a new automation rule in the Microsoft 365 Defender portal.

Automated investigation and remediation (AIR) rules in Microsoft 365 Defender allow you to define automated actions—such as quarantining a file—when a specific alert is triggered. This is the native mechanism for orchestrating response actions based on alert conditions, directly supporting the requirement to automatically quarantine a file upon alert generation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Add an indicator of compromise for the file.

    Why it's wrong here

    An indicator of compromise flags or blocks a file by hash, IP or certificate, but it does not itself quarantine in response to an alert. It is tempting because indicators do drive detection and blocking; however, the automated quarantine action belongs to AIR rules, which act on investigation findings.

  • ✗

    Configure a device control policy.

    Why it's wrong here

    Device control policies govern peripheral usage such as USB mass storage, not file quarantine triggered by an alert. It is tempting because device control does block files, but only by device or media class; automated investigation and remediation rules are what quarantine files based on alert evidence.

  • ✓

    Create a new automation rule in the Microsoft 365 Defender portal.

    Why this is correct

    Creating an automation rule in the Microsoft 365 Defender portal directly satisfies the requirement to quarantine a file when a specific alert triggers. Automation rules evaluate alerts and execute response actions such as quarantine, unlike custom detections, which only generate alerts, or device groups, which merely scope remediation levels.

  • ✗

    Create an attack surface reduction rule.

    Why it's wrong here

    Attack surface reduction rules block behaviours such as Office spawning child processes, not quarantine a specific file on alert. It is tempting because ASR does prevent malicious activity, but it operates on behavioural heuristics rather than the alert-triggered remediation that AIR rules provide.

Go deeper

Related to this question

About these practice questions

Courseiva writes every MD-102 question from scratch — 556 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.