Design security operations, identity, and compliance capabilities →easyMultiple ChoiceObjective-mapped
Automated Investigation and Response (AIR) in Microsoft Defender XDR
Your organization uses Microsoft Defender XDR to detect and respond to threats. The SOC team wants to automatically isolate a device when a high-severity incident is confirmed. Which automation feature should you configure?
Quick Answer
Automated investigation and response is the Defender XDR feature purpose-built to act on a confirmed incident rather than just flag it, which is the distinction that matters here — the SOC doesn't want a device isolated on a low-confidence alert, they want it isolated once an incident is confirmed high-severity, and AIR is designed around exactly that trigger. It works through automated playbooks that investigate alerts across endpoints, email, and identities, correlate them into a confirmed incident using machine learning, and then carry out predefined response actions like isolating an affected device, all without a SOC analyst manually initiating each step. This is what elevates AIR above simple alerting or detection features that only surface a signal for a human to act on: AIR closes the loop from detection to containment automatically, which is precisely the 'no manual intervention' requirement in the scenario. Any question describing an automatic containment action, like device isolation, tied specifically to confirmed severity rather than raw detection is pointing at AIR as the mechanism responsible for that response.
⚠ Common exam trap
Many candidates confuse EDR's detection capabilities with automated response, forgetting that AIR is the specific feature that orchestrates and executes automatic containment actions like device isolation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Automated investigation and response (AIR)
Automated investigation and response (AIR) in Microsoft Defender XDR is designed to automatically respond to confirmed high-severity incidents, including isolating devices, without manual intervention. This feature leverages playbooks and machine learning to contain threats rapidly, aligning with the SOC's requirement for automatic isolation upon incident confirmation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Defender for Office 365 Safe Attachments policy
Why it's wrong here
Safe Attachments is for email, not device isolation.
- ✓
Automated investigation and response (AIR)
Why this is correct
AIR can automatically isolate devices based on incident severity.
- ✗
Manual device isolation from Microsoft 365 Defender portal
Why it's wrong here
Manual isolation requires human intervention.
- ✗
Microsoft Defender for Endpoint's endpoint detection and response (EDR)
Why it's wrong here
EDR provides detection, not automatic isolation.
Go deeper
Related to this question
About these practice questions
This SC-100 question is part of Courseiva's 208-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SC-100
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Your organization uses Microsoft Defender for Endpoint (MDE) and wants to implement automated investigation and response (AIR) for ransomware. You need to ensure that when a suspicious file is detected, the investigation is automatically started and the file is contained. What should you configure?
medium- ✓ A.Configure the automated investigation and response capabilities in MDE.
- B.Create a custom detection rule in Microsoft 365 Defender.
- C.Enable attack surface reduction rules.
- D.Add the file hash to the indicators of compromise list.
Why A: Automated investigation and response (AIR) in Microsoft Defender for Endpoint can be configured to automatically start investigations and take containment actions like isolating files when suspicious activity is detected. Option B is incorrect because custom detection rules in Microsoft 365 Defender create alerts but do not automatically take response actions like containment; they require manual or automated remediation rules. Option C is incorrect because attack surface reduction rules reduce the attack surface by blocking common techniques but do not automate investigation and response for specific detections. Option D is incorrect because adding file hashes to the indicators of compromise list blocks or allows known threats but does not automate the investigation process.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.