Courseiva

MD-102 Manage and maintain devices Practice Question

Your organization uses Microsoft Defender for Endpoint. You need to configure automatic investigation and response for devices. Which setting in the Microsoft Defender XDR portal should you adjust?

⚠ Common exam trap

Many candidates confuse the 'Automated investigation and response' configuration with the 'Alert queue' or 'Threat analytics' because they all appear under the same XDR portal section, but only the AIR setting directly manages the automation behavior for device-level response actions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Automated investigation and response

The correct setting is 'Automated investigation and response' because it directly controls the configuration of automatic investigation and response (AIR) capabilities in Microsoft Defender for Endpoint. This setting allows administrators to enable or disable automated investigations, set the automation level (e.g., full, semi, or no automation), and define remediation actions for devices. Without adjusting this setting, the automatic investigation and response workflow cannot be tailored to the organization's security requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Automated investigation and response

    Why this is correct

    Automated investigation and response in the Microsoft Defender XDR portal governs whether alerts trigger automatic investigation and remediation actions on devices. Enabling it there satisfies the requirement to configure automatic investigation and response for onboarded endpoints.

  • ✗

    Threat analytics

    Why it's wrong here

    Threat analytics publishes intelligence reports about emerging threats; it configures no automated investigation or response behaviour. It is tempting because it is a Defender XDR feature relating to threats, and would be correct when researching an active campaign to decide manual remediation steps.

  • ✗

    Device inventory

    Why it's wrong here

    Device inventory merely lists onboarded devices and their health; it exposes no setting that turns on automatic investigation and response. It is tempting because it is where devices appear, and would be the right place when checking onboarding status or excluding a device from automated actions.

  • ✗

    Alert queue

    Why it's wrong here

    The alert queue only lists and triages generated alerts; it holds no toggle that enables automated investigation and response. It is tempting because alerts are the visible output of detection, and reviewing them is the correct task when manually triaging incidents rather than configuring automation.

Go deeper

Related to this question

About these practice questions

Courseiva writes every MD-102 question from scratch — 556 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.