Courseiva

MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR

A security administrator wants to automatically block a file that is detected as malware on one endpoint from being executed on all other endpoints in the organization. Which Microsoft Defender for Endpoint capability provides this?

⚠ Common exam trap

Many candidates confuse automated investigation and remediation with proactive controls like attack surface reduction rules, but AIR is specifically the reactive, automated response capability that can block a detected file across all endpoints.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Automated investigation and remediation

Automated investigation and remediation (AIR) in Microsoft Defender for Endpoint is designed to automatically respond to detected threats by containing or blocking malicious files across the organization. When malware is detected on one endpoint, AIR can trigger a remediation action (e.g., blocking the file hash) that is propagated to all other endpoints via the Microsoft Defender security center, preventing execution elsewhere.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Attack surface reduction rules

    Why it's wrong here

    Attack surface reduction rules are designed to reduce exploit surface by blocking behaviors commonly used by malware, such as Office launching child processes, credential theft, or execution of suspicious scripts. However, they rely on pattern-based and heuristic detection of attack techniques, not on identifying and blocking a specific file hash that has already been proven malicious. Thus, while ASR rules prevent many attacks, they do not perform the organization-wide file containment that is needed after a malware detection occurs on one endpoint.

  • Network protection

    Why it's wrong here

    Network protection, part of Windows Defender Exploit Guard, intercepts outbound connections to dangerous domains, IPs, and URLs, thereby preventing a device from reaching command-and-control servers or phishing hosts. It operates strictly at the network layer and evaluates connection destinations, not the files that travel over the network or run on endpoints. As a result, it cannot block a specific malware file after it has been detected, because file-level blocking is a host-based, remediation-oriented action unrelated to network connection filtering.

  • Tamper protection

    Why it's wrong here

    Tamper protection is a security control that safeguards Microsoft Defender's own settings and processes by preventing unauthorized changes to features like real-time protection, cloud-delivered protection, and antivirus configurations. It is fundamentally a self-defense mechanism for the security agent, not a response action that can be invoked to contain a specific detected artifact. Blocking a file, such as a known malware sample, is a post-detection remediation activity; tamper protection neither initiates nor enforces such file-level blocking across endpoints.

  • Automated investigation and remediation

    Why this is correct

    Automated investigation and remediation (AIR) in Microsoft Defender for Endpoint directly matches the requirement: when malware is detected on one device, AIR automatically performs an investigation, and then can take response actions including blocking the file's hash and containing the threat across the entire organization. By leveraging cloud-based intelligence, AIR can propagate the block to all endpoints before the malware has a chance to spread or re-enter. This is the only option that provides a post-detection, automated, organization-wide file-blocking capability.

About these practice questions

One of 241 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.