MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
A security administrator wants to simulate a realistic phishing attack to train users and measure their susceptibility. The simulation should be run from within Microsoft Defender XDR and provide detailed reporting. Which feature should the administrator use?
⚠ Common exam trap
Many candidates confuse Attack Simulation Training with Advanced Hunting, thinking that hunting queries can simulate attacks, but Advanced Hunting is purely a read-only data exploration tool with no simulation or user training features.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Attack Simulation Training
Attack Simulation Training in Microsoft Defender XDR allows security administrators to create and launch realistic phishing campaigns directly from the Microsoft 365 Defender portal. It provides detailed reporting on user interactions, such as who clicked the link or entered credentials, enabling measurement of user susceptibility and targeted training follow-ups.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Advanced Hunting
Why it's wrong here
Advanced Hunting is a security analytics tool in Microsoft 365 Defender that lets you query raw event data using KQL to proactively hunt for threats across endpoints, email, and identities. It is entirely reactive and investigative—it does not generate or send phishing messages, track user click-through, or deliver any awareness training. Thus, while useful for detecting compromise, it cannot simulate attacks or measure user susceptibility, making it the wrong choice here.
- ✓
Attack Simulation Training
Why this is correct
Attack Simulation Training is the dedicated feature in Microsoft Defender for Office 365 designed to create realistic phishing simulations and assign targeted training to users who interact with them. It provides prebuilt simulation templates, tracks metrics like click rate and credential submission, and automates follow-up training to improve user resilience. This matches the requirement to simulate a phishing attack and measure user response, so it is the correct answer.
- ✗
Automated Investigation and Response
Why it's wrong here
Automated Investigation and Response (AIR) is a set of playbooks in Microsoft 365 Defender that automatically investigate active alerts, contain compromised accounts, and remediate threats like malware or phishing emails. It operates on real, ongoing incidents and executes remediation actions on devices and mailboxes, not on user behavior or training. Since it reacts to actual attacks rather than simulating them or measuring user awareness, it is not suitable for this scenario.
- ✗
Threat Analytics
Why it's wrong here
Threat Analytics is a reporting and intelligence feature in Microsoft 365 Defender that provides detailed assessments of active threat actors, attack techniques, and recommended mitigations based on global and organizational telemetry. It serves as an informational source for defenders, offering insights into campaigns and vulnerabilities, but it lacks any interactive simulation or training capability. It cannot create phishing attacks or gauge user performance, so it does not meet the stated requirement.
Go deeper
Related to this question
Learn chapter
Exchange Online Protection and Anti-Phishing
Key term
Microsoft Defender XDR
Microsoft Defender XDR is a unified security platform that automatically correlates alerts from across an organization's endpoints, email, identities, and cloud apps to stop complex attacks.
Key term
Phishing
Phishing is a type of cyber attack where criminals impersonate legitimate organizations or individuals to trick victims into revealing sensitive information such as passwords, credit card numbers, or personal data.
About these practice questions
This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.