Courseiva

MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR

A company's security team needs to investigate a suspicious email that was reported by a user. The email was not blocked by Exchange Online Protection (EOP) and was delivered to the user's inbox. The security team wants to use Microsoft Defender XDR to analyze the email and its attachments. Which feature should they use to submit the email for automated investigation?

⚠ Common exam trap

MS-102 often tests the distinction between investigation tools — the trap is confusing Threat Explorer (viewing threats) with Submissions (reporting threats for analysis), or picking Advanced Hunting when the question asks about submitting a specific email.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Submissions

Microsoft Defender XDR's Submissions feature (under Email & Collaboration > Submissions) allows security teams to submit suspicious emails, attachments, and URLs to Microsoft for automated analysis. When a user reports a phish that EOP missed, the admin can submit it via Submissions, which triggers automated investigation, detonation, and re-classification. This is the correct tool for analyzing a specific reported email and its attachments.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Submissions

    Why this is correct

    Submissions in Microsoft Defender XDR lets administrators send user-reported or suspicious emails, including attachments, for automated investigation and rescanning. It satisfies the requirement because the message was delivered, so it must be submitted manually rather than relying on EOP blocking.

  • ✗

    Advanced Hunting

    Why it's wrong here

    Advanced Hunting runs KQL queries against up to 30 days of raw telemetry; it cannot submit an email to the automated investigation and response engine. It is the right tool for proactively querying EmailEvents or DeviceFileEvents tables, but the scenario requires triggering automated analysis of a specific delivered message.

  • ✗

    Threat Explorer

    Why it's wrong here

    Threat Explorer provides interactive views and filtering of email and file data for manual investigation, but it does not submit items to automated investigation and response. It suits hunting through delivered mail by sender, URL or verdict; the scenario instead requires handing the message to the automated analysis pipeline.

  • ✗

    Attack Simulator

    Why it's wrong here

    Attack Simulator generates phishing campaigns and training simulations to test user awareness; it does not accept a real reported email for analysis. It would be the correct choice when launching a simulated credential-harvesting campaign, but here the team needs automated investigation of an actual suspicious message already sitting in an inbox.

About these practice questions

This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.