Courseiva

MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR

Which THREE features are included in Microsoft Defender for Office 365 Plan 2 but NOT in Plan 1? (Choose three.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Automated Investigation and Response (AIR)

Options C, D, and E are correct. Plan 2 includes Automated Investigation and Response (AIR), Threat Explorer, and Attack Simulation Training. Plan 1 includes anti-phishing policies (A) and Safe Links (B), so they are not correct.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Anti-phishing policies

    Why it's wrong here

    Anti-phishing policies are a foundational protection layer in Microsoft Defender for Office 365 Plan 1, not an exclusive Plan 2 feature. They provide core anti-phishing defenses such as spoof intelligence, impersonation detection, and mailbox intelligence, which are essential but already available in the lower tier. Their inclusion in Plan 1 means they cannot be the distinguishing feature that identifies a Plan 2 license.

  • Safe Links

    Why it's wrong here

    Safe Links is a time-of-click URL scanning capability that protects users from malicious links in email messages and Office documents. This feature is part of Microsoft Defender for Office 365 Plan 1, where it is automatically enabled and configured via Safe Links policies. Because Plan 1 already includes Safe Links, it is incorrect to single it out as a Plan 2-only feature.

  • Automated Investigation and Response (AIR)

    Why this is correct

    Automated Investigation and Response (AIR) is a premium Plan 2 capability that uses orchestration and automation to investigate alerts, analyze threat signals, and take recommended or automated remediation actions. It goes beyond passive detection by proactively resolving incidents without requiring continuous manual oversight, making it a key differentiator for Plan 2 licensing.

  • Threat Explorer

    Why this is correct

    Threat Explorer is a real-time, interactive investigative tool that lets security teams view and analyze threat detections, search across mail and collaboration data, and take targeted actions on threats. It is exclusively available in Microsoft Defender for Office 365 Plan 2, providing advanced hunting and incident response capabilities that are not present in Plan 1.

  • Attack Simulation Training

    Why this is correct

    Attack Simulation Training is a Plan 2 feature that allows administrators to create and launch realistic phishing and password-attack simulations, then deliver user education modules based on the results. It is designed to measure and improve an organization's security posture by training employees against social engineering attacks. This feature is licensed only with Plan 2, reinforcing its classification as a Plan 2 exclusive.

Go deeper

Related to this question

About these practice questions

Courseiva writes every MS-102 question from scratch — 241 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.