Courseiva

MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR

Your organization uses Microsoft Defender for Endpoint. You need to configure a rule that automatically isolates a device from the network when a specific threat is detected, but only if the device is in a specific device group. Which approach should you use?

⚠ Common exam trap

Test-takers frequently confuse automation rules with custom detection rules, thinking custom detection rules can also trigger automated actions, but only automation rules provide the device group scoping and direct remediation actions like isolation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Automation rule

Automation rules in Microsoft Defender for Endpoint allow you to define automated actions, such as isolating a device, based on specific conditions like threat severity and device group membership. This directly meets the requirement to isolate only devices in a specific group when a specific threat is detected, as automation rules support granular scoping by device group.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Indicator of compromise (IoC)

    Why it's wrong here

    An indicator of compromise (IoC) in Microsoft Defender for Endpoint defines a custom reputation for entities like files, hashes, IP addresses, or domains, enabling block, allow, or alert behaviors. These indicators do not perform response actions such as isolating a device from the network; they only affect how Defender handles the specified entity. Device isolation is an automated response action that must be triggered by a separate automation rule.

  • ✓

    Automation rule

    Why this is correct

    An automation rule in Microsoft 365 Defender allows you to define conditions based on alert or incident properties and then automatically run a series of actions, including Microsoft Defender for Endpoint's isolate device response action. By specifying a condition like 'Alert severity' or 'Threat category,' you can trigger device isolation without manual intervention. Automation rules are the appropriate mechanism because they combine trigger conditions with remediation actions like isolation.

  • ✗

    Custom detection rule

    Why it's wrong here

    A custom detection rule relies on Advanced Hunting KQL queries to detect suspicious behavior and create an alert, but that alert is the end product of the rule. Device isolation is an automated remediation action that the custom detection rule cannot invoke on its own. To isolate a device from the generated alert, you would still need an automation rule to respond to that alert.

  • ✗

    Group policy in Intune

    Why it's wrong here

    Group Policy in Intune (or on-premises) manages device configuration and compliance settings, such as Windows security policies or BitLocker, through configuration profiles. It has no native integration with Defender for Endpoint's automated response engine, and it cannot dynamically isolate a device when a threat is detected. Device isolation is a real-time response action triggered within Defender for Endpoint, requiring an automation rule rather than a configuration management policy.

About these practice questions

One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.