MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
You are a security administrator for a company that uses Microsoft Defender XDR. You need to configure automated investigation and response (AIR) in Microsoft Defender for Endpoint to automatically remediate threats. You want to ensure that when a high-severity alert is triggered, the device is isolated and the malicious file is quarantined without manual intervention. Which setting should you configure?
⚠ Common exam trap
The trap here is assuming that custom detection rules or alert notifications can perform remediation, but they only detect or notify, not act.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Automation level in Microsoft Defender for Endpoint settings
The automation level setting in Microsoft Defender for Endpoint controls whether automated investigations automatically remediate threats. Setting it to full automation enables the system to isolate devices and quarantine files without human intervention when high-severity alerts occur, meeting the requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Automation level in Microsoft Defender for Endpoint settings
Why this is correct
The automation level setting in Microsoft Defender for Endpoint determines how automated investigations and response actions are taken. Setting it to 'Full - remediate threats automatically' allows the system to automatically isolate devices and quarantine files upon high-severity alerts, achieving the required no-manual-intervention remediation.
- ✗
Advanced hunting custom detection rules
Why it's wrong here
Custom detection rules in advanced hunting generate alerts based on scheduled queries but do not perform automatic remediation actions like device isolation or file quarantine. They are used for detection, not for automated response, so they cannot fulfill the requirement.
- ✗
Attack surface reduction rules
Why it's wrong here
Attack surface reduction (ASR) rules block certain risky behaviors, such as Office applications creating child processes, but they do not provide automated investigation and remediation of threats. ASR rules are preventive and do not isolate devices or quarantine files automatically upon alert.
- ✗
Alert notification rules in Microsoft 365 Defender
Why it's wrong here
Alert notification rules are used to send email notifications about alerts to specified recipients. They do not control automated remediation actions such as device isolation or file quarantine, so configuring them would not achieve the automatic response requirement.
Go deeper
Related to this question
Learn chapter
Intune Device Management
Key term
Microsoft Defender XDR
Microsoft Defender XDR is a unified security platform that automatically correlates alerts from across an organization's endpoints, email, identities, and cloud apps to stop complex attacks.
Key term
Quarantine
Quarantine is a security process that isolates a potentially malicious file, email, or device from the rest of the system to prevent harm while it is analyzed or remediated.
About these practice questions
This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.