MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
You are a security administrator for a company that uses Microsoft Defender XDR. An analyst reports that a user's device is showing signs of compromise, and you need to isolate the device from the network while preserving the ability to collect forensic evidence. The device is running Windows 11 and is onboarded to Microsoft Defender for Endpoint. Which action should you take in the Microsoft 365 Defender portal?
⚠ Common exam trap
A common mix-up: candidates confuse isolation with other response actions like running a scan or collecting an investigation package, which do not contain the threat.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Isolate the device from the network.
Isolating the device from the network is the correct action because it immediately contains the threat by restricting network communication while still allowing the Defender for Endpoint service to communicate with the device. This enables further investigation and evidence collection without risking lateral movement or data exfiltration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Isolate the device from the network.
Why this is correct
Isolating the device from the network disconnects it from all network traffic except for the Defender for Endpoint service, allowing you to contain the threat while preserving the ability to collect forensic evidence remotely. This is the correct action to meet the requirement.
- ✗
Run a full antivirus scan on the device.
Why it's wrong here
A full antivirus scan can detect and remove malware, but it does not isolate the device from the network. The device would remain connected, allowing potential lateral movement or data exfiltration. This action does not meet the requirement of isolating the device while preserving forensic evidence.
- ✗
Collect an investigation package from the device.
Why it's wrong here
Collecting an investigation package gathers forensic data but does not isolate the device. The device remains connected to the network, so the threat is not contained. This action is typically performed after isolation or as part of an investigation, not as a containment measure.
- ✗
Initiate an automated investigation on the device.
Why it's wrong here
Automated investigation can gather evidence and remediate threats, but it does not immediately isolate the device from the network. The device remains online, and the investigation may take time. Isolation is a separate action that must be explicitly performed to contain the threat.
Go deeper
Related to this question
Learn chapter
Threat Analytics Dashboard
Key term
XDR
XDR, or Extended Detection and Response, is a unified security platform that collects and correlates data across multiple security layers—endpoints, networks, servers, cloud workloads, and email—to improve threat detection and enable faster response.
Key term
Microsoft Defender XDR
Microsoft Defender XDR is a unified security platform that automatically correlates alerts from across an organization's endpoints, email, identities, and cloud apps to stop complex attacks.
About these practice questions
Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.