MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
A security administrator wants to automatically block a file that is detected as malware on one endpoint from being executed on all other endpoints in the organization. Which Microsoft Defender for Endpoint capability provides this?
⚠ Common exam trap
Many candidates confuse automated investigation and remediation with proactive controls like attack surface reduction rules, but AIR is specifically the reactive, automated response capability that can block a detected file across all endpoints.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Automated investigation and remediation
Automated investigation and remediation (AIR) in Microsoft Defender for Endpoint is designed to automatically respond to detected threats by containing or blocking malicious files across the organization. When malware is detected on one endpoint, AIR can trigger a remediation action (e.g., blocking the file hash) that is propagated to all other endpoints via the Microsoft Defender security center, preventing execution elsewhere.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Attack surface reduction rules
Why it's wrong here
Attack surface reduction rules are designed to reduce exploit surface by blocking behaviors commonly used by malware, such as Office launching child processes, credential theft, or execution of suspicious scripts. However, they rely on pattern-based and heuristic detection of attack techniques, not on identifying and blocking a specific file hash that has already been proven malicious. Thus, while ASR rules prevent many attacks, they do not perform the organization-wide file containment that is needed after a malware detection occurs on one endpoint.
- ✗
Network protection
Why it's wrong here
Network protection, part of Windows Defender Exploit Guard, intercepts outbound connections to dangerous domains, IPs, and URLs, thereby preventing a device from reaching command-and-control servers or phishing hosts. It operates strictly at the network layer and evaluates connection destinations, not the files that travel over the network or run on endpoints. As a result, it cannot block a specific malware file after it has been detected, because file-level blocking is a host-based, remediation-oriented action unrelated to network connection filtering.
- ✗
Tamper protection
Why it's wrong here
Tamper protection is a security control that safeguards Microsoft Defender's own settings and processes by preventing unauthorized changes to features like real-time protection, cloud-delivered protection, and antivirus configurations. It is fundamentally a self-defense mechanism for the security agent, not a response action that can be invoked to contain a specific detected artifact. Blocking a file, such as a known malware sample, is a post-detection remediation activity; tamper protection neither initiates nor enforces such file-level blocking across endpoints.
- ✓
Automated investigation and remediation
Why this is correct
Automated investigation and remediation (AIR) in Microsoft Defender for Endpoint directly matches the requirement: when malware is detected on one device, AIR automatically performs an investigation, and then can take response actions including blocking the file's hash and containing the threat across the entire organization. By leveraging cloud-based intelligence, AIR can propagate the block to all endpoints before the malware has a chance to spread or re-enter. This is the only option that provides a post-detection, automated, organization-wide file-blocking capability.
Go deeper
Related to this question
Learn chapter
Microsoft 365 Tenant Setup
Key term
Malware
Malware is any software intentionally designed to cause damage, disrupt operations, steal data, or gain unauthorized access to computer systems.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
One of 241 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.