MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
A security administrator needs to create an automated investigation and response (AIR) playbook that automatically isolates a device whenever a high-severity alert from Microsoft Defender for Endpoint is generated. The playbook should run without requiring manual approval. Which capability in Microsoft 365 Defender should the administrator configure?
⚠ Common exam trap
Candidates often confuse custom detection rules (Option B) with automated response capabilities, mistakenly thinking that creating a detection rule can also trigger automatic remediation, when in fact custom detection rules only generate alerts and require an AIR policy or manual action to respond.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Automated investigation and response (AIR) action policy
Automated Investigation and Response (AIR) action policies in Microsoft 365 Defender allow administrators to define automated remediation actions—such as device isolation—that execute automatically when specific alert conditions are met, without requiring manual approval. The policy can be configured to trigger on high-severity alerts from Microsoft Defender for Endpoint, enabling fully automated containment of compromised devices.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Automated investigation and response (AIR) action policy
Why this is correct
AIR action policies allow administrators to define automatic responses to specific alert types. By setting the isolation action for high-severity alerts from Microsoft Defender for Endpoint, the device can be isolated automatically without manual intervention.
- ✗
Custom detection rule
Why it's wrong here
Custom detection rules let you create alerts and incidents from advanced hunting queries, but they do not include automated response actions or a playbook definition. When a custom detection triggers, you still need a separate Microsoft 365 Defender AIR policy to define actions such as device isolation. Thus, a custom detection rule alone cannot fulfill the requirement to automatically isolate a device.
- ✗
Threat analytics
Why it's wrong here
Threat analytics is a threat intelligence reporting module that provides insights into active attackers, campaigns, and mitigation recommendations, but it offers no mechanism to configure automated responses. It is designed for analysis and awareness, not for executing actions like device isolation on real alerts. Therefore, it cannot serve as a playbook for automated investigation and response.
- ✗
Attack simulation training
Why it's wrong here
Attack simulation training is used to launch simulated phishing campaigns and run user awareness training, which has no connection to real-world alert triggers or endpoint response actions. It neither detects nor responds to actual threats and cannot be configured to perform automated device isolation. This makes it unsuitable as an automated investigation and response playbook.
Go deeper
Related to this question
Learn chapter
Microsoft 365 Tenant Setup
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
About these practice questions
This MS-102 question is part of Courseiva's 241-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.