Courseiva

MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR

Which THREE features are included in Microsoft Defender for Office 365 Plan 2 but NOT in Plan 1? (Choose three.)

⚠ Common exam trap

MS-102 often tests the boundary between P1 protection features and P2 investigation features, so candidates incorrectly include Safe Links or anti-phishing as P2 exclusives.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Automated Investigation and Response (AIR)

Automated Investigation and Response (AIR) (C) is exclusive to Defender for Office 365 Plan 2, as it uses automated playbooks to investigate and remediate threats, which Plan 1 does not include. Threat Explorer (D) is also a Plan 2-only feature, providing real-time and historical threat hunting and reporting capabilities that are absent from Plan 1. Attack Simulation Training (E) is likewise included only in Plan 2, enabling organizations to run simulated phishing and social engineering attacks to train users. Anti-phishing policies (A) and Safe Links (B) are available in both Plan 1 and Plan 2, so they are not correct answers for features unique to Plan 2.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Anti-phishing policies

    Why it's wrong here

    Anti-phishing policies are a foundational protection layer in Microsoft Defender for Office 365 Plan 1, not an exclusive Plan 2 feature. They provide core anti-phishing defenses such as spoof intelligence, impersonation detection, and mailbox intelligence, which are essential but already available in the lower tier. Their inclusion in Plan 1 means they cannot be the distinguishing feature that identifies a Plan 2 license.

  • ✗

    Safe Links

    Why it's wrong here

    Safe Links is a time-of-click URL scanning capability that protects users from malicious links in email messages and Office documents. This feature is part of Microsoft Defender for Office 365 Plan 1, where it is automatically enabled and configured via Safe Links policies. Because Plan 1 already includes Safe Links, it is incorrect to single it out as a Plan 2-only feature.

  • ✓

    Automated Investigation and Response (AIR)

    Why this is correct

    Automated Investigation and Response (AIR) is a premium Plan 2 capability that uses orchestration and automation to investigate alerts, analyze threat signals, and take recommended or automated remediation actions. It goes beyond passive detection by proactively resolving incidents without requiring continuous manual oversight, making it a key differentiator for Plan 2 licensing.

  • ✓

    Threat Explorer

    Why this is correct

    Threat Explorer is a real-time, interactive investigative tool that lets security teams view and analyze threat detections, search across mail and collaboration data, and take targeted actions on threats. It is exclusively available in Microsoft Defender for Office 365 Plan 2, providing advanced hunting and incident response capabilities that are not present in Plan 1.

  • ✓

    Attack Simulation Training

    Why this is correct

    Attack Simulation Training is a Plan 2 feature that allows administrators to create and launch realistic phishing and password-attack simulations, then deliver user education modules based on the results. It is designed to measure and improve an organization's security posture by training employees against social engineering attacks. This feature is licensed only with Plan 2, reinforcing its classification as a Plan 2 exclusive.

Go deeper

Related to this question

About these practice questions

Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.