Courseiva

MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR

A security administrator needs to create an automated investigation and response (AIR) playbook that automatically isolates a device whenever a high-severity alert from Microsoft Defender for Endpoint is generated. The playbook should run without requiring manual approval. Which capability in Microsoft 365 Defender should the administrator configure?

⚠ Common exam trap

Candidates often confuse custom detection rules (Option B) with automated response capabilities, mistakenly thinking that creating a detection rule can also trigger automatic remediation, when in fact custom detection rules only generate alerts and require an AIR policy or manual action to respond.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Automated investigation and response (AIR) action policy

Automated Investigation and Response (AIR) action policies in Microsoft 365 Defender allow administrators to define automated remediation actions—such as device isolation—that execute automatically when specific alert conditions are met, without requiring manual approval. The policy can be configured to trigger on high-severity alerts from Microsoft Defender for Endpoint, enabling fully automated containment of compromised devices.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Automated investigation and response (AIR) action policy

    Why this is correct

    AIR action policies allow administrators to define automatic responses to specific alert types. By setting the isolation action for high-severity alerts from Microsoft Defender for Endpoint, the device can be isolated automatically without manual intervention.

  • Custom detection rule

    Why it's wrong here

    Custom detection rules let you create alerts and incidents from advanced hunting queries, but they do not include automated response actions or a playbook definition. When a custom detection triggers, you still need a separate Microsoft 365 Defender AIR policy to define actions such as device isolation. Thus, a custom detection rule alone cannot fulfill the requirement to automatically isolate a device.

  • Threat analytics

    Why it's wrong here

    Threat analytics is a threat intelligence reporting module that provides insights into active attackers, campaigns, and mitigation recommendations, but it offers no mechanism to configure automated responses. It is designed for analysis and awareness, not for executing actions like device isolation on real alerts. Therefore, it cannot serve as a playbook for automated investigation and response.

  • Attack simulation training

    Why it's wrong here

    Attack simulation training is used to launch simulated phishing campaigns and run user awareness training, which has no connection to real-world alert triggers or endpoint response actions. It neither detects nor responds to actual threats and cannot be configured to perform automated device isolation. This makes it unsuitable as an automated investigation and response playbook.

About these practice questions

This MS-102 question is part of Courseiva's 241-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.