Courseiva

MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR

Network Topology
Microsoft Defender for Endpoint device configuration profile<!>Refer to the exhibit.```xml<DeviceConfiguration><DefenderForEndpoint><EnableAutomatedInvestigation>true</EnableAutomatedInvestigation><AlertSeverityForAutomatedInvestigation>Medium</AlertSeverityForAutomatedInvestigation><EmailNotification><Enabled>true</Enabled><Recipients>admin@contoso.com</Recipients></EmailNotification></DefenderForEndpoint></DeviceConfiguration>```

Refer to the exhibit. You deploy this configuration profile to Windows devices. What is the most likely outcome?

⚠ Common exam trap

Many candidates confuse the severity filter with a binary on/off toggle, or assume that specifying a single email recipient sends notifications to all admins by default, when in fact the recipient list is explicitly defined.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Automated investigation will be triggered for alerts with severity Medium and above, and email notifications will be sent to admin@contoso.com.

The configuration profile sets the automated investigation action to 'Medium or higher' and specifies a single email recipient (admin@contoso.com). This means Defender for Endpoint will trigger automated investigations for alerts with severity Medium, High, or Critical, and send email notifications only to the listed address, not to all admins.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Automated investigation will be triggered for alerts with severity Medium and above, and email notifications will be sent to admin@contoso.com.

    Why this is correct

    This configuration profile is correctly interpreted because it explicitly sets the automated investigation severity threshold to 'Medium and above', meaning alerts classified as Medium, High, or Critical will trigger an automated investigation. Additionally, email notifications are enabled and addressed specifically to admin@contoso.com, not to all administrators, which matches the 'To' field in the policy. The combination of an inclusive severity threshold and a targeted recipient list is exactly what the deployment produces.

  • ✗

    Automated investigation will be triggered only for alerts with severity High, and email notifications will be sent to all admins.

    Why it's wrong here

    The threshold for automated investigation is not limited to High severity. The policy uses a minimum severity level of Medium, which includes Medium and High (and Critical), so alerts at Medium severity would also trigger investigations. Furthermore, email notifications are sent only to admin@contoso.com as defined by the recipient list, not broadcast to all admins; the policy does not contain any setting to notify the global administrator or all tenant admins automatically.

  • ✗

    Automated investigation will be disabled, and email notifications will be sent to admin@contoso.com.

    Why it's wrong here

    The configuration actually enables automated investigation rather than disabling it. The policy likely contains an 'EnableAutomatedInvestigation' or similar setting set to true, which turns on the feature. While the notification part is correct—emails go to admin@contoso.com—the assertion that automated investigation is disabled contradicts the core functionality of the policy, so the overall statement is false.

  • ✗

    Automated investigation will be triggered for all alerts regardless of severity, and no email notifications will be sent.

    Why it's wrong here

    This option is false because the severity threshold is not set to all alerts; it is specifically configured for Medium and above, which excludes Low severity alerts. Additionally, email notifications are enabled and delivered to admin@contoso.com, contrary to the claim that no notifications are sent. The policy therefore filters by both severity and recipient, rather than investigating everything silently, so the behavior described here does not match the configuration.

About these practice questions

This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.