Courseiva

MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR

Your organization uses Microsoft Defender for Endpoint (MDE). You need to configure an automated investigation and response (AIR) capability that will automatically remediate a confirmed malware infection on endpoints. Which action should you enable?

⚠ Common exam trap

It's easy for candidates to confuse enabling a specific remediation action (like 'Isolate device') with configuring the overall automated investigation and response capability, whereas the correct approach is to enable 'Automatically resolve alerts' which then triggers the appropriate remediation actions based on the investigation verdict.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Automatically resolve alerts

Enabling 'Automatically resolve alerts' in Microsoft Defender for Endpoint's automated investigation and response (AIR) capabilities allows the system to automatically remediate confirmed malware infections by resolving the alert and applying the appropriate remediation actions (e.g., quarantining files, terminating processes) without manual intervention. This setting ensures that once an investigation confirms a threat, the response is executed automatically, aligning with the requirement for automated remediation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Run antivirus scan

    Why it's wrong here

    In MDE, running an antivirus scan is a discrete remediation action that is typically initiated manually or through a scheduled policy, and it is not the configuration that governs alert resolution. An AV scan can detect and clean threats on a device, but it does not orchestrate the end-to-end automated investigation flow or mark alerts as resolved. Therefore, selecting it would not enable automatic alert closure.

  • ✗

    Notify users via email

    Why it's wrong here

    Email notification is purely a communication control: it informs users about a detected incident but has no effect on the threat state, file status, or alert lifecycle. Sending messages cannot quarantine malicious files, stop processes, or trigger remediation, and it leaves the alert in an active state. Because notifications do not perform any remediation, they cannot be the mechanism that automatically resolves alerts.

  • ✓

    Automatically resolve alerts

    Why this is correct

    Enabling the 'Automatically resolve alerts' option instructs Defender for Endpoint's automated investigation engine to execute appropriate remediation actions and then close the alert when the investigation reaches a conclusion. This setting is the key to connecting determined threat severity with response steps, allowing alert incidents to be resolved without manual triage. It ensures that if remediation succeeds, the alert is automatically marked as resolved.

  • ✗

    Isolate device

    Why it's wrong here

    Isolating a device is a containment action that severs the endpoint's network connections to prevent malware from spreading, but it does not eliminate the malicious files or processes on that machine. Because the underlying threat remains intact, the alert cannot be considered remediated and will continue to require manual cleaning or reimaging before resolution. Thus, device isolation alone will not cause the alert to be automatically resolved.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.