Courseiva

Automating Device Containment in Microsoft Defender XDR

You are designing an incident response plan using Microsoft Defender XDR. You want to automate the containment of compromised devices when a high-severity incident is detected. What should you configure?

Quick Answer

The answer is to enable automated investigation and response (AIR) in Microsoft Defender XDR. This is correct because AIR uses built-in automation to contain compromised devices at machine-level when a high-severity incident is detected, executing actions like isolating the device from the network without manual intervention. On the MS-102 exam, this question tests your understanding of how Microsoft Defender XDR’s native automation differs from external tools like Microsoft Sentinel playbooks, which require separate triggers, or custom detection rules that only generate alerts. A common trap is confusing device groups—which manage policy scope, not automation—with AIR’s containment logic. Remember the memory tip: “AIR contains, rules alert, groups govern, playbooks prompt.”

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable automated investigation and response (AIR) in Microsoft Defender XDR

C is correct because automated investigation and response (AIR) in Microsoft Defender XDR can automatically contain devices when a high-severity incident is detected. A is incorrect because custom detection rules in Microsoft Defender for Endpoint only create alerts; they do not automatically contain devices. B is incorrect because device groups are used for management and policy assignment, not for automated containment. D is incorrect because playbooks in Microsoft Sentinel require manual triggering or other automation; they are not configured within Defender XDR.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure custom detection rules in Microsoft Defender for Endpoint

    Why it's wrong here

    Custom detection rules generate alerts, but do not automatically contain.

  • ✗

    Configure device groups in Microsoft Defender for Endpoint

    Why it's wrong here

    Device groups organize devices, but do not automate containment.

  • ✓

    Enable automated investigation and response (AIR) in Microsoft Defender XDR

    Why this is correct

    AIR can automatically contain devices based on incident severity.

  • ✗

    Create a playbook in Microsoft Sentinel

    Why it's wrong here

    Playbooks are for Microsoft Sentinel, not directly for Defender XDR.

About these practice questions

Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

3 more ways this is tested on MS-102

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Your organization uses Microsoft Defender for Endpoint. You need to ensure that when a user clicks a malicious link in an email, the endpoint is automatically isolated. What should you configure?

medium
  • A.Enable network protection in block mode.
  • ✓ B.Configure an automated investigation and response (AIR) playbook for device isolation.
  • C.Configure attack surface reduction rules to block the link.
  • D.Create a custom detection rule to trigger isolation.

Why B: Automated investigation and response (AIR) can be configured to automatically isolate a device when a malicious link is clicked, based on alerts from Microsoft Defender for Endpoint. Option A is incorrect because network protection in block mode blocks connections to malicious domains/IPs but does not isolate the device. Option C is incorrect because attack surface reduction rules reduce the attack surface by blocking behaviors but do not automatically isolate. Option D is incorrect because while custom detection rules can trigger isolation, the built-in AIR playbook is the recommended automated method.

Variation 2. Your organization uses Microsoft Defender for Endpoint. You need to ensure that when a device with a high-risk vulnerability is detected, it is automatically isolated from the network. What should you configure?

medium
  • A.Run an advanced hunting query to identify high-risk devices.
  • ✓ B.Create an automation rule in Microsoft Defender XDR.
  • C.Create a device group and assign a device configuration policy.
  • D.Enable vulnerability management in Microsoft Defender for Endpoint.

Why B: Automation rules in Microsoft Defender XDR allow you to automatically take action (such as isolating a device) when triggered by a vulnerability detection. Option A is incorrect because advanced hunting queries are for investigating threats, not automating responses. Option C is incorrect because device groups and configuration policies manage settings, not automated incident responses. Option D is incorrect because vulnerability management only provides visibility into vulnerabilities, it does not automate isolation actions.

Variation 3. Your organization uses Microsoft Defender for Endpoint (Plan 2) and Microsoft Defender for Identity. A user reports that their device is running slowly and exhibiting unusual network traffic. You investigate in Microsoft Defender XDR and see a high number of alerts for the device. You need to determine if the device is compromised and, if so, initiate an automated investigation. What should you do first?

hard
  • A.Isolate the device from the network immediately
  • B.Initiate a Live Response session to gather forensic data
  • ✓ C.Use the Microsoft Defender XDR portal to trigger an automated investigation on the device
  • D.Run a full antivirus scan from Microsoft Defender Antivirus

Why C: Using the Microsoft Defender XDR portal to trigger an automated investigation leverages the full XDR capabilities to analyze the device and determine if it is compromised. Option A is incorrect because isolating the device is a containment action, not the first step to determine compromise. Option B is incorrect because Live Response is a manual forensic tool, not an automated investigation. Option D is incorrect because running a full antivirus scan is not an automated investigation and may not detect advanced threats.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.