MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
Exhibit
{
"exhibit_text": "You run the following KQL query in Microsoft Defender XDR Advanced Hunting:\n\n`DeviceNetworkEvents`\n`| where Timestamp > ago(1d)`\n`| where ActionType == "ConnectionSuccess"`\n`| where RemoteIPType == "Public"`\n`| summarize Count = count() by DeviceName, RemoteIP`\n`| where Count > 100`\n`| order by Count desc`\n\nThe query returns a list of devices that have made over 100 successful connections to public IPs in the last day. You need to investigate further."Refer to the exhibit. You run the KQL query and see that a device named 'WORKSTATION42' has made 1500 connections to a public IP address 203.0.113.55 in the last day. You suspect the device may be compromised. What should you do next to gain the most context?
⚠ Common exam trap
Candidates may jump to containment (isolate) or blocking, but the question asks for the next step to gain context, so investigation via additional queries is correct.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Expand the query to join with DeviceProcessEvents to see which process initiated the connections
Expanding the query to join with DeviceProcessEvents will provide context on which process initiated the connections, helping determine if the activity is malicious or benign. This is the next logical step in an investigation before taking containment actions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Isolate the device immediately using Microsoft Defender for Endpoint
Why it's wrong here
Isolating the device immediately in Microsoft Defender for Endpoint is premature because it halts the compromise without first collecting the forensic evidence needed to understand the attack. The isolation action does not reveal the process, command line, or parent process associated with the suspicious connection, and it can also destroy volatile data such as active network sessions if the investigation would have captured them. MDE's isolation should be a containment step taken after the alert is confirmed, not the first investigative action, especially when a benign application could be the source.
- ✓
Expand the query to join with DeviceProcessEvents to see which process initiated the connections
Why this is correct
Expanding the Advanced Hunting query with a join to DeviceProcessEvents is the correct next step because it lets you identify which executable initiated each connection. DeviceNetworkEvents already records InitiatingProcessId, but combining it with DeviceProcessEvents using DeviceId, Timestamp, and ProcessId enables you to see the full process details, command-line arguments, and parent process. This tells you whether the traffic is from a known legitimate application or an unknown/malicious process, giving you a foundation for a reasoned containment decision.
- ✗
Add the IP address to the Tenant Allow/Block List to block it
Why it's wrong here
Adding the IP address to the Tenant Allow/Block List will not block the outbound traffic from the device because that list only operates on messages and files in Exchange Online Protection and Microsoft Defender for Office 365, not on endpoint network connections. The Tenant Allow/Block List is used to override email filtering verdicts for senders, domains, URLs, or file hashes, and it cannot enforce a block at the network adapter level on a Windows device. For blocking an IP from endpoints, you would need a custom indicator in Microsoft Defender for Endpoint, and only after you understand the process and confirm the threat.
- ✗
Create a Safe Links policy to block the IP address
Why it's wrong here
Creating a Safe Links policy cannot block an IP address because Safe Links is a URL-detonation and time-of-click protection feature for links in email messages and Microsoft 365 apps, not a network-layer firewall or IP filter. Even if you entered the IP into a URL block list, it would only affect occurrences of that literal URL string in supported apps, not the raw IP connections being made from the endpoint. This action would be both ineffective at stopping the traffic and unrelated to the investigative process that should occur first.
Go deeper
Related to this question
About these practice questions
Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.