20+ practice questions focused on Manage security and threats by using Microsoft Defender XDR — one of the most tested topics on the Microsoft 365 Administrator MS-102 exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Manage security and threats by using Microsoft Defender XDR PracticeA security operations team uses Microsoft Defender XDR. They want to create a custom detection rule that alerts when a specific process (e.g., wscript.exe) launches from a user's temp directory and then performs a network connection to an external IP. Which advanced hunting query language should they use?
Explanation: Microsoft Defender XDR uses Kusto Query Language (KQL) for advanced hunting queries, including custom detection rules. KQL allows querying the DeviceProcessEvents and DeviceNetworkEvents tables to correlate process launches with network connections, making it the correct choice for this scenario.
A security operations team wants to receive real-time alerts when a user is at high risk of having their account compromised based on unusual sign-in patterns. Which Microsoft Defender XDR component should they configure?
Explanation: Microsoft Defender for Identity (MDI) is the correct component because it is specifically designed to detect and alert on identity-based threats, including unusual sign-in patterns that indicate a high risk of account compromise. MDI uses behavioral analytics and machine learning to monitor on-premises Active Directory and Microsoft Entra ID sign-in logs for anomalies such as impossible travel, unusual login times, or suspicious credential usage, triggering real-time alerts. This directly matches the requirement for real-time alerts on user risk from unusual sign-in patterns.
A security analyst wants to create a custom detection rule in Microsoft Defender XDR that triggers when a user receives a phishing email and later clicks a link to a known malicious domain from their device. The rule will use advanced hunting queries. Which two tables should be joined to detect the click event from the device?
Explanation: Detecting a user clicking a link to a known malicious domain from their device requires joining the email URL information (EmailUrlInfo) with the device-level network event (DeviceNetworkEvents). EmailUrlInfo contains the URLs from emails, and DeviceNetworkEvents records outbound network connections from devices, including the destination domain. Joining these tables on the URL or domain allows you to correlate the email link with the subsequent device click event. Option B (EmailEvents and DeviceNetworkEvents) is incorrect because EmailEvents does not provide the specific URL clicked; it only gives email-level metadata. The URL must come from EmailUrlInfo.
A security analyst wants to search for instances where a user received a phishing email that was delivered to their inbox, and then later clicked a link within that email that led to a known malicious domain. Which two advanced hunting tables should be joined to identify both the email delivery and the link click events? (Choose the option that correctly identifies the primary table pair.)
Explanation: Only option A is correct. EmailEvents records email delivery events and includes the NetworkMessageId. DeviceEvents captures user actions such as URL clicks (ActionType 'UrlClick' or 'PhishClick') and also includes the NetworkMessageId. Joining these two tables on NetworkMessageId allows the analyst to correlate a delivered email with a subsequent click. Option B is incorrect because EmailPostDeliveryEvents does contain link click actions, but DeviceNetworkEvents logs network connections, not link clicks. To identify a link click, the analyst needs the user action event, not the network connection. Moreover, DeviceNetworkEvents may not reliably include the NetworkMessageId for all link clicks. Therefore, the correct pair is A.
A security analyst is investigating a potential lateral movement attack. They need to identify which processes were created on a compromised device and then which network connections were made by those processes. Which two advanced hunting tables should the analyst join in a KQL query?
Explanation: To identify processes created on a compromised device and then the network connections made by those processes, the analyst must join DeviceProcessEvents (process creation) with DeviceNetworkEvents (network connections) on DeviceId and ProcessId. This directly maps each process to its outbound connections, enabling detection of lateral movement indicators like SMB, RDP, or WinRM traffic. Option C (IdentityLogonEvents and DeviceProcessEvents) is incorrect because it does not include network connection data, which is essential for the investigation.
+15 more Manage security and threats by using Microsoft Defender XDR questions available
Practice all Manage security and threats by using Microsoft Defender XDR questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Manage security and threats by using Microsoft Defender XDR. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Manage security and threats by using Microsoft Defender XDR questions on the MS-102 frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Manage security and threats by using Microsoft Defender XDR is tested as part of the Microsoft 365 Administrator MS-102 blueprint. Practicing with targeted Manage security and threats by using Microsoft Defender XDR questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free MS-102 practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Manage security and threats by using Microsoft Defender XDR is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Manage security and threats by using Microsoft Defender XDR practice session with instant scoring and detailed explanations.
Start Manage security and threats by using Microsoft Defender XDR Practice →