MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
Your organization uses Microsoft Defender for Endpoint. You need to configure a rule that automatically isolates a device from the network when a specific threat is detected, but only if the device is in a specific device group. Which approach should you use?
⚠ Common exam trap
Test-takers frequently confuse automation rules with custom detection rules, thinking custom detection rules can also trigger automated actions, but only automation rules provide the device group scoping and direct remediation actions like isolation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Automation rule
Automation rules in Microsoft Defender for Endpoint allow you to define automated actions, such as isolating a device, based on specific conditions like threat severity and device group membership. This directly meets the requirement to isolate only devices in a specific group when a specific threat is detected, as automation rules support granular scoping by device group.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Indicator of compromise (IoC)
Why it's wrong here
An indicator of compromise (IoC) in Microsoft Defender for Endpoint defines a custom reputation for entities like files, hashes, IP addresses, or domains, enabling block, allow, or alert behaviors. These indicators do not perform response actions such as isolating a device from the network; they only affect how Defender handles the specified entity. Device isolation is an automated response action that must be triggered by a separate automation rule.
- ✓
Automation rule
Why this is correct
An automation rule in Microsoft 365 Defender allows you to define conditions based on alert or incident properties and then automatically run a series of actions, including Microsoft Defender for Endpoint's isolate device response action. By specifying a condition like 'Alert severity' or 'Threat category,' you can trigger device isolation without manual intervention. Automation rules are the appropriate mechanism because they combine trigger conditions with remediation actions like isolation.
- ✗
Custom detection rule
Why it's wrong here
A custom detection rule relies on Advanced Hunting KQL queries to detect suspicious behavior and create an alert, but that alert is the end product of the rule. Device isolation is an automated remediation action that the custom detection rule cannot invoke on its own. To isolate a device from the generated alert, you would still need an automation rule to respond to that alert.
- ✗
Group policy in Intune
Why it's wrong here
Group Policy in Intune (or on-premises) manages device configuration and compliance settings, such as Windows security policies or BitLocker, through configuration profiles. It has no native integration with Defender for Endpoint's automated response engine, and it cannot dynamically isolate a device when a threat is detected. Device isolation is a real-time response action triggered within Defender for Endpoint, requiring an automation rule rather than a configuration management policy.
Go deeper
Related to this question
Learn chapter
Defender for Endpoint Deployment via Intune
Key term
Threat
A threat is any potential danger that could harm a computer system, network, or data, whether from a malicious hacker, a natural disaster, or an accidental mistake.
Key term
Device group
A device group is a logical collection of devices managed together for applying policies, configurations, and updates in an enterprise IT environment.
About these practice questions
One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.