Courseiva

MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR

You are a security administrator for a company that uses Microsoft Defender XDR. You need to configure automated investigation and response (AIR) in Microsoft Defender for Endpoint to automatically remediate threats. You want to ensure that when a high-severity alert is triggered, the device is isolated and the malicious file is quarantined without manual intervention. Which setting should you configure?

⚠ Common exam trap

The trap here is assuming that custom detection rules or alert notifications can perform remediation, but they only detect or notify, not act.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Automation level in Microsoft Defender for Endpoint settings

The automation level setting in Microsoft Defender for Endpoint controls whether automated investigations automatically remediate threats. Setting it to full automation enables the system to isolate devices and quarantine files without human intervention when high-severity alerts occur, meeting the requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Automation level in Microsoft Defender for Endpoint settings

    Why this is correct

    The automation level setting in Microsoft Defender for Endpoint determines how automated investigations and response actions are taken. Setting it to 'Full - remediate threats automatically' allows the system to automatically isolate devices and quarantine files upon high-severity alerts, achieving the required no-manual-intervention remediation.

  • ✗

    Advanced hunting custom detection rules

    Why it's wrong here

    Custom detection rules in advanced hunting generate alerts based on scheduled queries but do not perform automatic remediation actions like device isolation or file quarantine. They are used for detection, not for automated response, so they cannot fulfill the requirement.

  • ✗

    Attack surface reduction rules

    Why it's wrong here

    Attack surface reduction (ASR) rules block certain risky behaviors, such as Office applications creating child processes, but they do not provide automated investigation and remediation of threats. ASR rules are preventive and do not isolate devices or quarantine files automatically upon alert.

  • ✗

    Alert notification rules in Microsoft 365 Defender

    Why it's wrong here

    Alert notification rules are used to send email notifications about alerts to specified recipients. They do not control automated remediation actions such as device isolation or file quarantine, so configuring them would not achieve the automatic response requirement.

About these practice questions

This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.