Courseiva

Unified Incident Management in Microsoft Defender XDR

A security administrator needs a single console to investigate and respond to a complex incident involving alerts from endpoints, email, and identities. Which Microsoft portal should they use?

Quick Answer

The Microsoft 365 Defender portal (security.microsoft.com) is the correct choice because it provides a unified incident management console that correlates alerts from Microsoft Defender for Endpoint, Office 365, and Identity into a single incident queue. This allows a security administrator to investigate and respond to a complex incident spanning endpoints, email, and identities from one pane of glass, leveraging automated investigation and response (AIR) to contain threats across all domains. On the MS-102 exam, this question tests your understanding of Microsoft’s extended detection and response (XDR) architecture and the specific portal that consolidates these security workloads. A common trap is confusing the Microsoft 365 Defender portal with the Azure Security Center or the Microsoft Purview compliance portal, which handle different scopes. Remember the memory tip: “One Defender to rule them all” — if the incident involves more than one workload (endpoint, email, identity), the answer is always the Microsoft 365 Defender portal.

⚠ Common exam trap

Test-takers frequently confuse Microsoft Sentinel (a SIEM) with the Microsoft 365 Defender portal (an XDR console), assuming that any security investigation must go through a SIEM, but the question specifically asks for the single console that natively correlates alerts from endpoints, email, and identities without additional data ingestion setup.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft 365 Defender portal

The Microsoft 365 Defender portal (security.microsoft.com) is the correct choice because it provides a unified incident management console that correlates alerts from Microsoft Defender for Endpoint, Microsoft Defender for Office 365, and Microsoft Defender for Identity. This allows the security administrator to investigate and respond to a complex incident spanning endpoints, email, and identities from a single pane of glass, leveraging automated investigation and response (AIR) capabilities.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Microsoft 365 Defender portal

    Why this is correct

    Microsoft 365 Defender portal unifies signals from Defender for Endpoint, Defender for Office 365, and Microsoft Entra ID Protection into one incident view, enabling cross-domain investigation and response. This single console satisfies the requirement to correlate endpoint, email, and identity alerts for a complex incident.

  • ✗

    Microsoft Sentinel

    Why it's wrong here

    Microsoft Sentinel is a SIEM/SOAR platform for ingesting and correlating logs, not the unified incident investigation console spanning endpoint, email, and identity alerts. It would be correct for building custom detections and automation, but Microsoft Defender XDR provides the integrated cross-domain incident view.

  • ✗

    Microsoft Defender for Cloud

    Why it's wrong here

    Microsoft Defender for Cloud protects cloud workloads and infrastructure, covering servers, containers and storage across Azure, AWS and GCP; it does not aggregate endpoint, email and identity alerts into one incident. It is tempting because it offers a central security posture view, which suits multicloud workload protection.

  • ✗

    Microsoft 365 compliance center

    Why it's wrong here

    The Microsoft 365 compliance centre handles data governance, eDiscovery, retention and insider risk, not cross-domain incident investigation and response. It is tempting because it centralises compliance alerts and cases, which suits regulatory investigations rather than correlating endpoint, email and identity detections.

About these practice questions

This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on MS-102

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. You are a security administrator for an organization that uses Microsoft Defender XDR. You want to provide your security operations team with a unified view of all incidents across endpoints, email, and identities. You also want to automate the creation of incidents when correlated alerts are detected. What should you do?

easy
  • ✓ A.Navigate to the Microsoft Defender XDR portal (security.microsoft.com) and use the Incidents view.
  • B.Open the Microsoft Defender for Endpoint portal and create a dashboard for all alerts.
  • C.Install Microsoft Sentinel and configure data connectors for all workloads.
  • D.Create a custom KQL query that correlates alerts from different sources and create a workbook.

Why A: The Microsoft Defender XDR portal (security.microsoft.com) provides a unified incident view and automatically correlates alerts from multiple workloads (endpoints, email, identities) into incidents. Option B is incorrect because Microsoft Defender for Endpoint portal focuses only on endpoint data, not the unified view across all services. Option C is incorrect because while Microsoft Sentinel can provide a unified view, it requires additional licensing, configuration, and does not automatically create incidents from correlated alerts without custom analytics rules. Option D is incorrect because custom KQL queries and workbooks provide visibility but do not automate incident creation; that requires built-in correlation from Microsoft Defender XDR.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.