Courseiva

MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR

You are a security administrator for a company that uses Microsoft Defender XDR. An analyst reports that a user's device is showing signs of compromise, and you need to isolate the device from the network while preserving the ability to collect forensic evidence. The device is running Windows 11 and is onboarded to Microsoft Defender for Endpoint. Which action should you take in the Microsoft 365 Defender portal?

⚠ Common exam trap

A common mix-up: candidates confuse isolation with other response actions like running a scan or collecting an investigation package, which do not contain the threat.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Isolate the device from the network.

Isolating the device from the network is the correct action because it immediately contains the threat by restricting network communication while still allowing the Defender for Endpoint service to communicate with the device. This enables further investigation and evidence collection without risking lateral movement or data exfiltration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Isolate the device from the network.

    Why this is correct

    Isolating the device from the network disconnects it from all network traffic except for the Defender for Endpoint service, allowing you to contain the threat while preserving the ability to collect forensic evidence remotely. This is the correct action to meet the requirement.

  • ✗

    Run a full antivirus scan on the device.

    Why it's wrong here

    A full antivirus scan can detect and remove malware, but it does not isolate the device from the network. The device would remain connected, allowing potential lateral movement or data exfiltration. This action does not meet the requirement of isolating the device while preserving forensic evidence.

  • ✗

    Collect an investigation package from the device.

    Why it's wrong here

    Collecting an investigation package gathers forensic data but does not isolate the device. The device remains connected to the network, so the threat is not contained. This action is typically performed after isolation or as part of an investigation, not as a containment measure.

  • ✗

    Initiate an automated investigation on the device.

    Why it's wrong here

    Automated investigation can gather evidence and remediate threats, but it does not immediately isolate the device from the network. The device remains online, and the investigation may take time. Isolation is a separate action that must be explicitly performed to contain the threat.

Go deeper

Related to this question

About these practice questions

Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.