Courseiva

MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR

A security analyst investigates a potential data exfiltration incident. The analyst identifies that a user's device has made multiple connections to an unknown external IP address using a custom port. Which Microsoft Defender XDR data source would provide the most detailed network communication logs for this investigation?

⚠ Common exam trap

Many candidates confuse the scope of Microsoft Defender for Cloud Apps, assuming it captures all network traffic, when in fact it only monitors cloud application usage and not raw endpoint network connections.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Microsoft Defender for Endpoint

Microsoft Defender for Endpoint (MDE) provides the most detailed network communication logs for this investigation because it captures full network events at the device level, including connections to external IP addresses on custom ports. MDE's advanced hunting schema includes the DeviceNetworkEvents table, which records source/destination IPs, ports, protocols, and process-level details, enabling precise analysis of anomalous outbound connections.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Microsoft Defender for Office 365

    Why it's wrong here

    Defender for Office 365 is an email security solution that inspects messages for phishing and malware, using safe attachments, safe links, and anti-spam policies. It does not collect endpoint network telemetry such as outbound TCP/UDP connections, so it cannot reveal the actual IP addresses or ports used during a suspected data exfiltration scenario.

  • Microsoft Defender for Cloud Apps

    Why it's wrong here

    Defender for Cloud Apps focuses on shadow IT discovery and access control for sanctioned cloud apps, relying on API connectors and proxy logs from your cloud providers. It does not ingest raw network packets or process-level connection data from an individual Windows or macOS device, making it unsuitable for identifying a direct exfiltration connection from the endpoint to a remote server.

  • Microsoft Defender for Endpoint

    Why this is correct

    Defender for Endpoint is the correct source because its sensor records detailed network communication events on each device, including the local process, destination IP, destination port, and protocol, which are stored in the DeviceNetworkEvents table for advanced hunting. These logs directly show an inbound or outbound connection that could represent exfiltration, with the process and user context needed for a full investigation.

  • Microsoft 365 Defender portal alerts

    Why it's wrong here

    The Microsoft 365 Defender portal alerts are aggregated notifications that combine signals from various products such as Defender for Endpoint, Defender for Office 365, and Defender for Cloud Apps. While an alert may highlight suspicious activity, it does not capture or store the underlying raw endpoint network connection logs; those live in the component product's data schema, so the alert alone cannot provide the IP addresses or process details required to prove exfiltration.

About these practice questions

This MS-102 question is part of Courseiva's 241-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.