MS-102 Automated investigation and response (AIR) Practice Question
Your organization uses Microsoft Defender XDR. You need to configure automatic response actions for a high-severity incident. Which TWO options are available in the Microsoft Defender XDR automated investigation and response capabilities?
⚠ Common exam trap
MS-102 often tests the specific automated response actions available in Defender XDR, and candidates may incorrectly assume that identity-related actions like password resets are included.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Isolate a device from the network
Option B (Isolate a device from the network) is correct because Microsoft Defender XDR automated investigation and response (AIR) can automatically contain a compromised endpoint by isolating it from the network, blocking most network traffic while preserving the Defender for Endpoint connection for remediation. Option C (Collect an investigation package from a device) is correct because AIR can automatically gather forensic data from an endpoint into an investigation package, which includes running processes, network connections, scheduled tasks, and other artifacts for analyst review. Option A (Create a mailbox rule to delete suspicious emails) is not an AIR response action; mailbox-level remediation in Defender XDR is performed through actions like soft delete, hard delete, or moving messages to Junk/Deleted Items, not by creating custom mailbox rules. Option D (Delegate mailbox permissions) is an Exchange administrative task unrelated to automated incident response. Option E (Reset user passwords) is not an automated response action provided by Defender XDR AIR; password resets are handled through identity management tools such as Microsoft Entra ID, not as a Defender XDR automated remediation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a mailbox rule to delete suspicious emails
Why it's wrong here
Mailbox rules are Exchange transport constructs, not Defender XDR automated investigation and response actions; AIR acts on devices, identities and mailboxes through its own remediation engine. It is tempting because email deletion is a genuine response to phishing, but that is performed via AIR's soft/hard delete actions or the Explorer, not a user-created mailbox rule.
- ✓
Isolate a device from the network
Why this is correct
Isolating a device from the network is a containment action Microsoft Defender XDR can execute automatically during automated investigation and response. It satisfies the stem's requirement for an available automatic response action, restricting lateral movement without deleting the device.
- ✓
Collect an investigation package from a device
Why this is correct
Collecting an investigation package gathers forensic artefacts from a device, and it is one of the automated investigation and response actions Microsoft Defender XDR can trigger automatically. It satisfies the stem's requirement for an available automatic response action on a high-severity incident.
- ✗
Delegate mailbox permissions
Why it's wrong here
Delegating mailbox permissions is an Exchange Online administrative action, not an automated investigation and response action; Defender XDR offers actions such as isolating a device, quarantining a file, or marking a user as compromised. It is tempting because mailbox delegation is a remediation-adjacent task, but it sits outside AIR's action catalogue.
- ✗
Reset user passwords
Why it's wrong here
Password resets belong to Microsoft Entra ID protection remediation, not Defender XDR's automated investigation and response action set, which covers device isolation, file quarantine, process termination and mailbox purge. It is tempting because compromised credentials drive incidents, but AIR cannot reset passwords; that requires Entra ID or on-premises tooling.
Go deeper
Related to this question
Learn chapter
Exchange Mobile Device Policies (OWA)
Key term
Microsoft Defender XDR
Microsoft Defender XDR is a unified security platform that automatically correlates alerts from across an organization's endpoints, email, identities, and cloud apps to stop complex attacks.
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
About these practice questions
This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.