Unified Incident Management in Microsoft Defender XDR
A security administrator needs a single console to investigate and respond to a complex incident involving alerts from endpoints, email, and identities. Which Microsoft portal should they use?
Quick Answer
The Microsoft 365 Defender portal (security.microsoft.com) is the correct choice because it provides a unified incident management console that correlates alerts from Microsoft Defender for Endpoint, Office 365, and Identity into a single incident queue. This allows a security administrator to investigate and respond to a complex incident spanning endpoints, email, and identities from one pane of glass, leveraging automated investigation and response (AIR) to contain threats across all domains. On the MS-102 exam, this question tests your understanding of Microsoft’s extended detection and response (XDR) architecture and the specific portal that consolidates these security workloads. A common trap is confusing the Microsoft 365 Defender portal with the Azure Security Center or the Microsoft Purview compliance portal, which handle different scopes. Remember the memory tip: “One Defender to rule them all” — if the incident involves more than one workload (endpoint, email, identity), the answer is always the Microsoft 365 Defender portal.
⚠ Common exam trap
Test-takers frequently confuse Microsoft Sentinel (a SIEM) with the Microsoft 365 Defender portal (an XDR console), assuming that any security investigation must go through a SIEM, but the question specifically asks for the single console that natively correlates alerts from endpoints, email, and identities without additional data ingestion setup.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft 365 Defender portal
The Microsoft 365 Defender portal (security.microsoft.com) is the correct choice because it provides a unified incident management console that correlates alerts from Microsoft Defender for Endpoint, Microsoft Defender for Office 365, and Microsoft Defender for Identity. This allows the security administrator to investigate and respond to a complex incident spanning endpoints, email, and identities from a single pane of glass, leveraging automated investigation and response (AIR) capabilities.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Microsoft 365 Defender portal
Why this is correct
Microsoft 365 Defender portal unifies signals from Defender for Endpoint, Defender for Office 365, and Microsoft Entra ID Protection into one incident view, enabling cross-domain investigation and response. This single console satisfies the requirement to correlate endpoint, email, and identity alerts for a complex incident.
- ✗
Microsoft Sentinel
Why it's wrong here
Microsoft Sentinel is a SIEM/SOAR platform for ingesting and correlating logs, not the unified incident investigation console spanning endpoint, email, and identity alerts. It would be correct for building custom detections and automation, but Microsoft Defender XDR provides the integrated cross-domain incident view.
- ✗
Microsoft Defender for Cloud
Why it's wrong here
Microsoft Defender for Cloud protects cloud workloads and infrastructure, covering servers, containers and storage across Azure, AWS and GCP; it does not aggregate endpoint, email and identity alerts into one incident. It is tempting because it offers a central security posture view, which suits multicloud workload protection.
- ✗
Microsoft 365 compliance center
Why it's wrong here
The Microsoft 365 compliance centre handles data governance, eDiscovery, retention and insider risk, not cross-domain incident investigation and response. It is tempting because it centralises compliance alerts and cases, which suits regulatory investigations rather than correlating endpoint, email and identity detections.
Go deeper
Related to this question
Learn chapter
Microsoft 365 Security Posture Improvement
Key term
Office 365
Office 365 is a cloud-based subscription service from Microsoft that provides access to productivity applications like Word, Excel, and Outlook, along with other cloud services, for a monthly or annual fee.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on MS-102
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. You are a security administrator for an organization that uses Microsoft Defender XDR. You want to provide your security operations team with a unified view of all incidents across endpoints, email, and identities. You also want to automate the creation of incidents when correlated alerts are detected. What should you do?
easy- ✓ A.Navigate to the Microsoft Defender XDR portal (security.microsoft.com) and use the Incidents view.
- B.Open the Microsoft Defender for Endpoint portal and create a dashboard for all alerts.
- C.Install Microsoft Sentinel and configure data connectors for all workloads.
- D.Create a custom KQL query that correlates alerts from different sources and create a workbook.
Why A: The Microsoft Defender XDR portal (security.microsoft.com) provides a unified incident view and automatically correlates alerts from multiple workloads (endpoints, email, identities) into incidents. Option B is incorrect because Microsoft Defender for Endpoint portal focuses only on endpoint data, not the unified view across all services. Option C is incorrect because while Microsoft Sentinel can provide a unified view, it requires additional licensing, configuration, and does not automatically create incidents from correlated alerts without custom analytics rules. Option D is incorrect because custom KQL queries and workbooks provide visibility but do not automate incident creation; that requires built-in correlation from Microsoft Defender XDR.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.