Courseiva

Automated Investigation and Response (AIR) in Microsoft Defender XDR

Your organization uses Microsoft Defender for Endpoint (MDE) and wants to implement automated investigation and response (AIR) for ransomware. You need to ensure that when a suspicious file is detected, the investigation is automatically started and the file is contained. What should you configure?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure the automated investigation and response capabilities in MDE.

Option A is correct because Microsoft Defender for Endpoint's automated investigation and response (AIR) capabilities are the built-in feature that automatically triggers investigations when alerts are raised and can take remediation actions such as containing or quarantining a suspicious file. Configuring AIR settings (including automation levels and remediation permissions) ensures that detections like ransomware lead to automatic investigation and file containment without manual intervention. Option B is incorrect because custom detection rules only generate alerts based on queries; they do not themselves perform automated investigation or containment. Option C is incorrect because attack surface reduction rules block specific risky behaviors but do not initiate automated investigations or file containment. Option D is incorrect because adding a file hash to the indicators of compromise list only creates a block/allow indicator and does not start an automated investigation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Configure the automated investigation and response capabilities in MDE.

    Why this is correct

    Configuring automated investigation and response (AIR) in Microsoft Defender for Endpoint enables the security solution to automatically run playbooks when alerts are triggered. These playbooks investigate the scope of the threat, contain the attack (e.g., isolating devices, blocking processes), and remediate the issue without manual intervention. AIR is the only listed option that directly addresses the requirement for automated response, because it integrates detection, investigation, and containment into one workflow.

  • ✗

    Create a custom detection rule in Microsoft 365 Defender.

    Why it's wrong here

    Creating a custom detection rule in Microsoft 365 Defender uses KQL to query your organization's telemetry and generate security alerts for custom-specified behaviors. While this provides tailored detection and can alert on suspicious activity, the alerts it produces require manual review and manual response actions. It does not include native automated investigation or automatic containment capabilities, so it cannot automate the response process described in the question.

  • ✗

    Enable attack surface reduction rules.

    Why it's wrong here

    Enabling attack surface reduction rules applies a set of preventative controls that block common malware techniques, such as Office apps spawning child processes or untrusted scripts launching. These rules are configured as policy baselines and are always proactive, meaning they attempt to stop malicious behavior before it occurs, but they do not investigate incidents that have already been detected. They offer no automated investigation, no alert triage, and no post-detection response actions, making them unrelated to automating response.

  • ✗

    Add the file hash to the indicators of compromise list.

    Why it's wrong here

    Adding a file hash to the indicators of compromise (IoC) list creates a static match criterion that either blocks or alerts on the hash across MDE devices. It is a deterministic, signature-based control that only acts on the exact hash you know about; it cannot investigate the broader incident, search for related attacker activity, or execute response actions like isolating a host. Thus, it provides blocking but not the automated investigation and response sought in the question.

About these practice questions

This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.