Courseiva

MS-102 Automated investigation and response (AIR) Practice Question

Your organization uses Microsoft Defender XDR. You need to configure automatic response actions for a high-severity incident. Which TWO options are available in the Microsoft Defender XDR automated investigation and response capabilities?

⚠ Common exam trap

MS-102 often tests the specific automated response actions available in Defender XDR, and candidates may incorrectly assume that identity-related actions like password resets are included.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Isolate a device from the network

Option B (Isolate a device from the network) is correct because Microsoft Defender XDR automated investigation and response (AIR) can automatically contain a compromised endpoint by isolating it from the network, blocking most network traffic while preserving the Defender for Endpoint connection for remediation. Option C (Collect an investigation package from a device) is correct because AIR can automatically gather forensic data from an endpoint into an investigation package, which includes running processes, network connections, scheduled tasks, and other artifacts for analyst review. Option A (Create a mailbox rule to delete suspicious emails) is not an AIR response action; mailbox-level remediation in Defender XDR is performed through actions like soft delete, hard delete, or moving messages to Junk/Deleted Items, not by creating custom mailbox rules. Option D (Delegate mailbox permissions) is an Exchange administrative task unrelated to automated incident response. Option E (Reset user passwords) is not an automated response action provided by Defender XDR AIR; password resets are handled through identity management tools such as Microsoft Entra ID, not as a Defender XDR automated remediation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a mailbox rule to delete suspicious emails

    Why it's wrong here

    Mailbox rules are Exchange transport constructs, not Defender XDR automated investigation and response actions; AIR acts on devices, identities and mailboxes through its own remediation engine. It is tempting because email deletion is a genuine response to phishing, but that is performed via AIR's soft/hard delete actions or the Explorer, not a user-created mailbox rule.

  • ✓

    Isolate a device from the network

    Why this is correct

    Isolating a device from the network is a containment action Microsoft Defender XDR can execute automatically during automated investigation and response. It satisfies the stem's requirement for an available automatic response action, restricting lateral movement without deleting the device.

  • ✓

    Collect an investigation package from a device

    Why this is correct

    Collecting an investigation package gathers forensic artefacts from a device, and it is one of the automated investigation and response actions Microsoft Defender XDR can trigger automatically. It satisfies the stem's requirement for an available automatic response action on a high-severity incident.

  • ✗

    Delegate mailbox permissions

    Why it's wrong here

    Delegating mailbox permissions is an Exchange Online administrative action, not an automated investigation and response action; Defender XDR offers actions such as isolating a device, quarantining a file, or marking a user as compromised. It is tempting because mailbox delegation is a remediation-adjacent task, but it sits outside AIR's action catalogue.

  • ✗

    Reset user passwords

    Why it's wrong here

    Password resets belong to Microsoft Entra ID protection remediation, not Defender XDR's automated investigation and response action set, which covers device isolation, file quarantine, process termination and mailbox purge. It is tempting because compromised credentials drive incidents, but AIR cannot reset passwords; that requires Entra ID or on-premises tooling.

About these practice questions

This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.