20+ practice questions focused on Manage security and threats by using Microsoft Defender XDR — one of the most tested topics on the Microsoft 365 Administrator MS-102 exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Manage security and threats by using Microsoft Defender XDR PracticeA security operations team uses Microsoft Defender XDR. They want to create a custom detection rule that alerts when a specific process (e.g., wscript.exe) launches from a user's temp directory and then performs a network connection to an external IP. Which advanced hunting query language should they use?
Explanation: Microsoft Defender XDR uses Kusto Query Language (KQL) for advanced hunting queries, including custom detection rules. KQL allows querying the DeviceProcessEvents and DeviceNetworkEvents tables to correlate process launches with network connections, making it the correct choice for this scenario.
A security operations team wants to receive real-time alerts when a user is at high risk of having their account compromised based on unusual sign-in patterns. Which Microsoft Defender XDR component should they configure?
Explanation: Microsoft Defender for Identity (MDI) is the correct component because it is specifically designed to detect and alert on identity-based threats, including unusual sign-in patterns that indicate a high risk of account compromise. MDI uses behavioral analytics and machine learning to monitor on-premises Active Directory and Azure AD sign-in logs for anomalies such as impossible travel, unusual login times, or suspicious credential usage, triggering real-time alerts. This directly matches the requirement for real-time alerts on user risk from unusual sign-in patterns.
A security analyst wants to create a custom detection rule in Microsoft Defender XDR that triggers when a user receives a phishing email and clicks a link to a known malicious domain. Which advanced hunting table should the analyst query to track the clicked URL?
Explanation: The EmailUrlInfo table in Advanced Hunting for Microsoft Defender XDR contains records of URLs that were present in emails, including the URL domain and whether the link was clicked. By joining EmailEvents with EmailUrlInfo on the NetworkMessageId, the analyst can identify when a user clicked a URL that leads to a known malicious domain, making it the correct table for tracking clicked URLs.
A ransomware alert is confirmed in Microsoft Defender XDR on a user device that is still communicating with other endpoints. What should the administrator do first to reduce spread while preserving the ability to investigate?
Explanation: Immediately isolating the affected device from the network stops the ransomware from spreading laterally to other endpoints via SMB, RDP, or other protocols, while preserving the device's state for forensic analysis. Microsoft Defender XDR's device isolation feature blocks all inbound and outbound communication except with the Defender for Endpoint cloud service, allowing investigation to continue without the risk of further infection.
A security administrator wants to create a custom detection rule in Microsoft Defender XDR that alerts when a device initiates an outbound TCP connection to a known malicious IP address on a non-standard port (e.g., port 4444). Which advanced hunting table should be queried to find these network connections?
Explanation: DeviceNetworkEvents is the correct table because it specifically captures network connection events, including outbound TCP connections to IP addresses and ports. This table contains fields like RemoteIP, RemotePort, and Protocol, making it ideal for detecting connections to known malicious IPs on non-standard ports such as 4444.
+15 more Manage security and threats by using Microsoft Defender XDR questions available
Practice all Manage security and threats by using Microsoft Defender XDR questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Manage security and threats by using Microsoft Defender XDR. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Manage security and threats by using Microsoft Defender XDR questions on the MS-102 frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Manage security and threats by using Microsoft Defender XDR is tested as part of the Microsoft 365 Administrator MS-102 blueprint. Practicing with targeted Manage security and threats by using Microsoft Defender XDR questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free MS-102 practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Manage security and threats by using Microsoft Defender XDR is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Manage security and threats by using Microsoft Defender XDR practice session with instant scoring and detailed explanations.
Start Manage security and threats by using Microsoft Defender XDR Practice →