MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
A security team wants to automatically investigate and remediate alerts generated from Microsoft Defender for Endpoint, Office 365, and Microsoft Entra ID. Which Microsoft Defender XDR capability should be configured?
⚠ Common exam trap
A common mix-up: candidates confuse Threat Analytics (which provides threat intelligence) with Automated Investigation and Response (which executes automated remediation), leading them to select A when the question explicitly asks for a capability that 'automatically investigates and remediates' alerts.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Automated Investigation and Response
Automated Investigation and Response (AIR) in Microsoft Defender XDR is the correct capability because it automatically triggers playbooks to investigate and remediate alerts across Microsoft Defender for Endpoint, Office 365, and Microsoft Entra ID. AIR uses predefined or custom automation rules to correlate signals from these sources, run investigations, and apply remediation actions like isolating devices or blocking accounts without manual intervention.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Threat Analytics
Why it's wrong here
Threat Analytics in Microsoft 365 Defender aggregates threat intelligence, attack campaigns, and vulnerability reports specific to the organization's exposed assets. While it provides valuable context on active threat actors and recommended mitigation actions, it only generates static incident intelligence and does not trigger any automated investigation or remediation workflow.
- ✓
Automated Investigation and Response
Why this is correct
Automated Investigation and Response (AIR) in Microsoft 365 Defender orchestrates security playbooks across endpoints, email, and identity signals, automatically collecting evidence, initiating investigations, and executing remediation actions such as quarantining files, suspending accounts, and blocking URLs. AIR leverages AI and predefined automation rules to contain low-impact threats in real time, with optional human approval for destructive actions.
- ✗
Advanced Hunting
Why it's wrong here
Advanced Hunting in the Microsoft 365 portal is a query-based Kusto Query Language (KQL) interface that enables security analysts to interactively search raw event data across up to 30 days, pivot across tables, and customize threat hypotheses. It is a manual and retrospective exercise that requires analytical skill to identify and interpret patterns, and it never performs automated response or remediation without an integrated custom action outside its workflow.
- ✗
Secure Score
Why it's wrong here
Secure Score is a configuration benchmarking tool that evaluates an organization's security posture by quantifying adoption of Microsoft security controls and recommending improvement actions with a scoring system. It measures the maturity of security settings but does not analyze live signals, escalate alerts, or execute automated remediation activities, making it entirely separate from incident response automation.
Go deeper
Related to this question
Learn chapter
Microsoft 365 Tenant Setup
Key term
XDR
XDR, or Extended Detection and Response, is a unified security platform that collects and correlates data across multiple security layers—endpoints, networks, servers, cloud workloads, and email—to improve threat detection and enable faster response.
Key term
Microsoft Defender XDR
Microsoft Defender XDR is a unified security platform that automatically correlates alerts from across an organization's endpoints, email, identities, and cloud apps to stop complex attacks.
About these practice questions
One of 241 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.