MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
A security analyst investigates a potential data exfiltration incident. The analyst identifies that a user's device has made multiple connections to an unknown external IP address using a custom port. Which Microsoft Defender XDR data source would provide the most detailed network communication logs for this investigation?
⚠ Common exam trap
Many candidates confuse the scope of Microsoft Defender for Cloud Apps, assuming it captures all network traffic, when in fact it only monitors cloud application usage and not raw endpoint network connections.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Defender for Endpoint
Microsoft Defender for Endpoint (MDE) provides the most detailed network communication logs for this investigation because it captures full network events at the device level, including connections to external IP addresses on custom ports. MDE's advanced hunting schema includes the DeviceNetworkEvents table, which records source/destination IPs, ports, protocols, and process-level details, enabling precise analysis of anomalous outbound connections.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Defender for Office 365
Why it's wrong here
Defender for Office 365 is an email security solution that inspects messages for phishing and malware, using safe attachments, safe links, and anti-spam policies. It does not collect endpoint network telemetry such as outbound TCP/UDP connections, so it cannot reveal the actual IP addresses or ports used during a suspected data exfiltration scenario.
- ✗
Microsoft Defender for Cloud Apps
Why it's wrong here
Defender for Cloud Apps focuses on shadow IT discovery and access control for sanctioned cloud apps, relying on API connectors and proxy logs from your cloud providers. It does not ingest raw network packets or process-level connection data from an individual Windows or macOS device, making it unsuitable for identifying a direct exfiltration connection from the endpoint to a remote server.
- ✓
Microsoft Defender for Endpoint
Why this is correct
Defender for Endpoint is the correct source because its sensor records detailed network communication events on each device, including the local process, destination IP, destination port, and protocol, which are stored in the DeviceNetworkEvents table for advanced hunting. These logs directly show an inbound or outbound connection that could represent exfiltration, with the process and user context needed for a full investigation.
- ✗
Microsoft 365 Defender portal alerts
Why it's wrong here
The Microsoft 365 Defender portal alerts are aggregated notifications that combine signals from various products such as Defender for Endpoint, Defender for Office 365, and Defender for Cloud Apps. While an alert may highlight suspicious activity, it does not capture or store the underlying raw endpoint network connection logs; those live in the component product's data schema, so the alert alone cannot provide the IP addresses or process details required to prove exfiltration.
Go deeper
Related to this question
Learn chapter
Microsoft 365 Tenant Setup
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
Key term
Microsoft Defender XDR
Microsoft Defender XDR is a unified security platform that automatically correlates alerts from across an organization's endpoints, email, identities, and cloud apps to stop complex attacks.
About these practice questions
This MS-102 question is part of Courseiva's 241-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.