MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
Your organization uses Microsoft Defender for Endpoint (Plan 2) and Microsoft Defender for Identity. A user reports that their device is running slowly and exhibiting unusual network traffic. You investigate in Microsoft Defender XDR and see a high number of alerts for the device. You need to determine if the device is compromised and, if so, initiate an automated investigation. What should you do first?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use the Microsoft Defender XDR portal to trigger an automated investigation on the device
Using the Microsoft Defender XDR portal to trigger an automated investigation leverages the full XDR capabilities to analyze the device and determine if it is compromised. Option A is incorrect because isolating the device is a containment action, not the first step to determine compromise. Option B is incorrect because Live Response is a manual forensic tool, not an automated investigation. Option D is incorrect because running a full antivirus scan is not an automated investigation and may not detect advanced threats.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Isolate the device from the network immediately
Why it's wrong here
Isolating the device cuts network connectivity before compromise is confirmed, and does not start an automated investigation; it is a containment action taken afterwards. It is tempting because isolation limits spread, and would be correct once investigation confirms active compromise requiring immediate containment.
- ✗
Initiate a Live Response session to gather forensic data
Why it's wrong here
Live Response collects forensic artefacts but does not itself trigger the automated investigation the scenario requires; the device must first be flagged for investigation in Defender XDR. It is tempting because forensic triage is valuable, and would be correct when deep artefact collection is needed after automated investigation has already run.
- ✓
Use the Microsoft Defender XDR portal to trigger an automated investigation on the device
Why this is correct
Triggering automated investigation from the Microsoft Defender XDR portal initiates the built-in response workflow, gathering evidence and applying remediation actions across the device. This directly addresses the requirement to determine compromise and start automated investigation.
- ✗
Run a full antivirus scan from Microsoft Defender Antivirus
Why it's wrong here
A full antivirus scan only inspects local files for known malware signatures; it cannot correlate the multi-source alerts already surfaced in Defender XDR or trigger the automated investigation the scenario requires. It is tempting because scanning is a familiar first response to a slow device, and would be right for suspected file-borne malware with no existing alerts.
Go deeper
Related to this question
Learn chapter
Microsoft Defender for Cloud Apps Administration
Key term
XDR
XDR, or Extended Detection and Response, is a unified security platform that collects and correlates data across multiple security layers—endpoints, networks, servers, cloud workloads, and email—to improve threat detection and enable faster response.
Key term
Microsoft Defender XDR
Microsoft Defender XDR is a unified security platform that automatically correlates alerts from across an organization's endpoints, email, identities, and cloud apps to stop complex attacks.
About these practice questions
This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.