Courseiva

MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR

A security administrator wants to configure Automated Investigation and Response (AIR) in Microsoft 365 Defender to automatically isolate a device when a high-severity alert for malware is detected. Which step is required?

⚠ Common exam trap

Watch out — candidates often confuse Microsoft Sentinel automation rules (which are for cross-source orchestration) with the device group automation settings in Microsoft Defender for Endpoint, leading them to pick Option A instead of the correct device group configuration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

C: Configure the device to be part of a device group and enable automation level.

To enable Automated Investigation and Response (AIR) in Microsoft Defender for Endpoint, the device must be added to a device group, and the automation level for that group must be set to 'Full – remediate threats automatically' or a similar level. This configuration allows Defender to automatically isolate a device when a high-severity malware alert is triggered, as part of the built-in AIR playbooks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • A: Create an automation rule in Microsoft Sentinel.

    Why it's wrong here

    Automation rules in Microsoft Sentinel orchestrate incident response across SIEM-connected sources and are designed for security operations center workflows, not for the automated, machine-driven investigation and remediation of a single endpoint's threats. AIR in Defender for Endpoint lives in the Microsoft 365 Defender portal and is governed by per-device-group automation levels; creating a Sentinel rule doesn't touch that Defender configuration. Therefore, it's not the correct way to configure AIR for Defender for Endpoint.

  • B: Create a custom detection rule in advanced hunting.

    Why it's wrong here

    Custom detection rules in advanced hunting let you write KQL queries that generate alert records when suspicious behavior matches your query, but they only raise alerts and do not define what automatic response actions occur. These alerts can be integrated into AIR, but the level of automation — for example, whether to automatically isolate a compromised device — is set on the device group, not inside the custom detection rule. So while useful for hunting and detection, this option does not configure the automated investigation and response capability itself.

  • C: Configure the device to be part of a device group and enable automation level.

    Why this is correct

    To actually turn on AIR, you place the device into a device group in Microsoft 365 Defender (under Endpoints > Device groups) and select an automation level such as 'Full - remediate threats automatically' or 'Automatic - investigate threats automatically.' The device group's automation level decides whether AIR runs automatically and what actions (isolation, file removal, etc.) can be taken without approval. Without a proper device group with the desired automation level, AIR's automatic actions remain disabled or require manual approval.

  • D: Enable auto-removal of malware from devices.

    Why it's wrong here

    Enabling auto-removal of malware is not a separate toggle you flip to configure AIR; it's one of many remediation actions (delete the file, quarantine it, etc.) that AIR can execute after an investigation determines the verdict. Whether that action happens automatically depends on the automation level assigned through the device group, not on a standalone enable flag. Thus, this option misidentifies a component action for the configuration mechanism.

About these practice questions

Courseiva writes every MS-102 question from scratch — 241 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.