MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
Your organization is a small business with 200 users. You use Microsoft 365 Business Premium, which includes Microsoft Defender for Business (the small business version of Defender for Endpoint) and Microsoft Defender for Office 365 Plan 1. You want to protect against ransomware by blocking malicious processes and behaviors on endpoints. You also need to enable automated investigation and response for common threats. However, your IT team has limited security expertise and wants a simple configuration that provides out-of-the-box protection without custom policies. What should you do?
⚠ Common exam trap
MS-102 often tests the difference between email-layer protection (Safe Attachments) and endpoint behavior blocking (ASR/AIR) — candidates pick Safe Attachments because 'ransomware' appears in email, but the question specifies blocking malicious processes on endpoints.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable the default security baseline in Microsoft Defender for Business, which includes attack surface reduction rules and automated investigation.
Microsoft Defender for Business includes a default security baseline that turns on recommended attack surface reduction (ASR) rules, next-generation antivirus, and automated investigation and response (AIR) out of the box. For a 200-user shop with limited security expertise, enabling this baseline delivers ransomware-blocking behavior rules and automated remediation without requiring custom policy authoring. This matches the requirement for simple, out-of-the-box protection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure Safe Attachments policies in Microsoft Defender for Office 365 to block ransomware attachments.
Why it's wrong here
Safe Attachments policies in Microsoft Defender for Office 365 detonate email attachments in a virtual sandbox to detect malicious payloads, but they operate solely at the email transport layer and do not monitor execution behavior on endpoints after delivery. Ransomware commonly arrives via other channels or triggers through scripts, links, or exploited vulnerabilities, so endpoint-level controls such as attack surface reduction rules are necessary. As a result, while Safe Attachments adds email protection, it is not the correct measure to block ransomware behaviors on devices.
- ✓
Enable the default security baseline in Microsoft Defender for Business, which includes attack surface reduction rules and automated investigation.
Why this is correct
Enabling the default security baseline in Microsoft Defender for Business provides a preset collection of endpoint protection settings, including attack surface reduction rules, real-time antivirus, tamper protection, and automated investigation and remediation. This baseline is curated by Microsoft to balance security with usability, making it ideal for small businesses that lack dedicated security staff. It directly addresses ransomware behaviors by blocking common exploit techniques and automatically responding to alerts without manual configuration.
- ✗
Create custom attack surface reduction rules in Microsoft Defender for Business to block ransomware behaviors.
Why it's wrong here
Creating custom attack surface reduction rules in Defender for Business requires deep expertise in your organization's legitimate applications and workflows, because misconfigured rules can generate false positives and disrupt production. The default security baseline already includes a vetted set of ASR rules specifically designed to cover ransomware behaviors such as credential theft and malicious script execution. For a 200-user small business, deploying custom rules before the baseline adds unnecessary complexity and is not the recommended first step.
- ✗
Deploy a third-party endpoint detection and response (EDR) solution alongside Microsoft Defender for Business.
Why it's wrong here
Deploying a third-party EDR solution alongside Microsoft Defender for Business would create a dual-agent environment, risking performance degradation, conflicting policies, and potential blind spots as each product may defer threat containment to the other. Microsoft Defender for Business is itself a comprehensive EDR solution that includes endpoint detection, response, and automated investigation, so adding another EDR is redundant. This approach also increases cost and administrative overhead, whereas the built-in baseline offers the necessary protection with minimal effort.
Go deeper
Related to this question
Learn chapter
Entra Connect Sync Rules and Filtering
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Microsoft 365
Microsoft 365 is a subscription-based cloud service from Microsoft that combines productivity tools like Office apps with security, device management, and online storage.
About these practice questions
Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.