MD-102 Protect devices Practice Question
Your organization uses Microsoft Defender for Cloud Apps (part of Microsoft Defender XDR). You need to detect when users access cloud apps from unauthorized locations. Which log source should you integrate to get location information?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra ID sign-in logs
Microsoft Defender for Cloud Apps can integrate with Microsoft Entra ID (Azure AD) to receive sign-in logs, which include IP address and location. Option B is wrong because Microsoft Intune device enrollment logs do not contain app access location. Option C is wrong because Microsoft Purview audit logs are for compliance, not real-time access. Option D is wrong because Microsoft Sentinel is a SIEM, not a source of location data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Microsoft Entra ID sign-in logs
Why this is correct
Entra ID sign-in logs provide IP addresses and geo-location for access events.
- ✗
Microsoft Intune device enrollment logs
Why it's wrong here
Intune device enrollment logs do not contain app access location, so they cannot provide location information for cloud app access.
- ✗
Microsoft Purview audit logs
Why it's wrong here
Purview logs are for compliance and data governance, not for real-time access location.
- ✗
Microsoft Sentinel
Why it's wrong here
Microsoft Sentinel is a SIEM, not a source of location data for Defender for Cloud Apps.
Go deeper
Related to this question
Learn chapter
Introduction to Endpoint Management in Microsoft 365
Key term
SIEM
SIEM (Security Information and Event Management) is a system that collects and analyzes log data from across an IT environment to detect and respond to security threats in real time.
Key term
Audit
An audit is a systematic, independent review of IT systems, processes, and controls to verify compliance with policies, standards, and regulations.
About these practice questions
One of 942 original MD-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.