Courseiva

CCNA Defender Xdr Security Questions

75 of 197 questions · Page 1/3 · Defender Xdr Security topic · Answers revealed

1
MCQhard

A security administrator wants to create a custom detection rule in Microsoft Defender XDR that alerts when a device initiates an outbound TCP connection to a known malicious IP address on a non-standard port (e.g., port 4444). Which advanced hunting table should be queried to find these network connections?

A.DeviceNetworkEvents
B.DeviceProcessEvents
C.EmailEvents
D.IdentityLogonEvents
AnswerA

DeviceNetworkEvents is the advanced hunting table in Microsoft Defender XDR that records each network connection event on monitored endpoints, including LocalIP, RemoteIP, LocalPort, RemotePort, Protocol, and ActionType (e.g., ConnectionAttempt, ConnectionSuccess). For a custom detection rule that needs to flag suspicious outbound connectivity, this table is the authoritative source because every row represents an actual device-initiated or accepted network connection with the exact destination endpoint needed for threshold or indicator matching.

Why this answer

DeviceNetworkEvents is the correct table because it specifically captures network connection events, including outbound TCP connections to IP addresses and ports. This table contains fields like RemoteIP, RemotePort, and Protocol, making it ideal for detecting connections to known malicious IPs on non-standard ports such as 4444.

Exam trap

The trap here is that candidates may confuse DeviceProcessEvents with network events because processes often initiate network connections, but DeviceProcessEvents does not contain network-level details like remote IP or port, leading to an incorrect choice.

How to eliminate wrong answers

Option B is wrong because DeviceProcessEvents logs process creation and execution events, not network connections; it lacks network-specific fields like RemoteIP or RemotePort. Option C is wrong because EmailEvents tracks email-related activities (delivery, phishing, etc.) and has no network connection data. Option D is wrong because IdentityLogonEvents records authentication and logon events for user identities, not device-level network traffic.

2
MCQeasy

A user reports that they cannot access a legitimate external website because Microsoft Defender for Endpoint is blocking it. The website is required for business. What should you do to allow access while maintaining security?

A.Exclude the device from the policy
B.Disable network protection for the device
C.Add the URL to the custom indicators allow list
D.Add the user to a custom group with lower security
AnswerC

Custom indicators in Microsoft Defender for Endpoint let you define allow entries that override block decisions for specific URLs, files or certificates. Adding the business URL to the allow list permits access while the rest of the indicator and protection stack stays enforced, satisfying the requirement to unblock one legitimate site.

Why this answer

Adding the URL to the custom indicators allow list in Microsoft Defender for Endpoint allows the specific URL while maintaining network protection for all other traffic. This is the granular approach to permit a legitimate business site without disabling security controls. The allow list overrides block actions for that indicator.

Exam trap

The trap is choosing to disable network protection or exclude the device entirely, which are heavy-handed and reduce security, instead of using the targeted allow list feature.

How to eliminate wrong answers

Option A is wrong because excluding the device from the policy removes all protections for that device, which is too broad and reduces security. Option B is wrong because disabling network protection for the device turns off the feature entirely, leaving the device vulnerable. Option D is wrong because adding the user to a custom group with lower security does not specifically allow the URL and may weaken security posture overall.

3
MCQmedium

A security administrator wants to prevent attackers from stealing credentials by blocking access to the Local Security Authority Subsystem Service (LSASS) from untrusted processes. Which Attack Surface Reduction (ASR) rule should the administrator enable to meet this requirement?

A.Block credential stealing from the Windows local security authority subsystem (lsass.exe).
B.Block executable files from running unless they meet a prevalence, age, or trusted list criterion.
C.Block Office applications from creating child processes.
D.Block persistence through Windows Management Instrumentation (WMI) event subscription.
AnswerA

LSASS is the Windows Local Security Authority Subsystem, which stores or caches credentials for single sign-on. Attackers use tools like Mimikatz or process injection to read the memory of lsass.exe and extract password hashes or plaintext credentials. The Block credential stealing from the Windows local security authority subsystem (lsass.exe) ASR rule prevents untrusted and non-signed processes from accessing lsass.exe, directly disrupting this credential-theft technique before it can succeed.

Why this answer

The ASR rule 'Block credential stealing from the Windows local security authority subsystem (lsass.exe)' (GUID: 9e6c4e1f-7d60-472f-ba1a-a39ef669e4b2) directly prevents untrusted processes from accessing LSASS memory, which is a common technique used by attackers to dump credentials via tools like Mimikatz. This rule blocks attempts to open lsass.exe with specific access rights (e.g., PROCESS_VM_READ) from non-trusted processes, thereby protecting credential material stored in LSASS.

Exam trap

The trap here is that candidates often confuse the 'Block credential stealing from LSASS' rule with other ASR rules that address different attack vectors, such as blocking executable files or Office child processes, because they all fall under the same 'Attack Surface Reduction' umbrella but target distinct behaviors.

How to eliminate wrong answers

Option B is wrong because it addresses executable file execution based on prevalence, age, or trusted list criteria, which is a different ASR rule (GUID: 01443614-cd74-433a-b99e-2ecdc07bfc25) focused on preventing untrusted or unknown executables from running, not specifically protecting LSASS from credential theft. Option C is wrong because it blocks Office applications from creating child processes (GUID: d4f940ab-401b-4efc-aadc-ad5f3c50688a), which prevents malware from using Office apps as a launch point but does not directly protect LSASS from credential access. Option D is wrong because it blocks persistence through WMI event subscription (GUID: e6db77e5-3df2-4cf1-b95a-636979351e5b), which prevents attackers from establishing persistence via WMI, but does not address the immediate credential theft from LSASS.

4
Multi-Selectmedium

Your organization uses Microsoft Defender for Endpoint. You need to configure advanced hunting to query device information. Which TWO tables contain device-related data?

Select 2 answers
A.AlertInfo
B.EmailEvents
C.IdentityLogonEvents
D.DeviceInfo
E.DeviceTvmInfoGathering
AnswersD, E

DeviceInfo is the core table in Microsoft Defender for Endpoint's Advanced Hunting that maintains a comprehensive inventory of all onboarded devices, including device ID, device name, OS platform, OS version, and last seen timestamp. It is the authoritative source for answering questions like 'which devices run Windows 11' or 'what OS versions are present.' By querying DeviceInfo and filtering on the OSVersion column, you can quickly retrieve the required device details.

Why this answer

DeviceInfo is correct because it is the primary table in Microsoft Defender for Endpoint advanced hunting that stores comprehensive device metadata, including OS version, device name, and sensor health. This table is essential for querying device-related information such as device inventory, onboarding status, and configuration details.

Exam trap

The trap here is that candidates may confuse tables that contain device identifiers (like IdentityLogonEvents or AlertInfo) with tables that store actual device-related data, leading them to select tables that only reference devices indirectly rather than containing device properties.

5
MCQeasy

You are a security administrator. You need to configure Microsoft Defender for Cloud Apps to detect anomalous user activities such as impossible travel. Which feature should you enable?

A.App Discovery
B.Cloud Discovery
C.Anomaly Detection policies
D.Conditional Access App Control
AnswerC

Anomaly Detection policies are the correct selection because they leverage User and Entity Behavior Analytics (UEBA) in Microsoft Defender for Cloud Apps to establish a baseline of normal user behavior and then generate alerts for deviations such as impossible travel, anonymous IP access, or mass file download. These policies employ machine learning to detect suspicious activities and can automatically trigger governance actions, directly meeting the security administrator's goal.

Why this answer

Anomaly Detection policies in Microsoft Defender for Cloud Apps are specifically designed to identify user behavior anomalies, such as impossible travel (a user logging in from two geographically distant locations within an impossible timeframe). These policies leverage machine learning and user entity behavior analytics (UEBA) to establish a baseline and flag deviations, making them the correct feature for detecting impossible travel.

Exam trap

The trap here is that candidates often confuse Cloud Discovery (which discovers cloud apps) with Anomaly Detection policies (which detect user behavior anomalies), leading them to select Cloud Discovery for impossible travel detection.

How to eliminate wrong answers

Option A is wrong because App Discovery is a feature that identifies shadow IT by discovering cloud apps used in the organization, not for detecting user behavior anomalies like impossible travel. Option B is wrong because Cloud Discovery focuses on discovering and assessing cloud app usage and risk, not on analyzing user activity patterns for anomalies. Option D is wrong because Conditional Access App Control is a reverse proxy feature that enforces access policies in real time (e.g., session monitoring or blocking downloads), but it does not perform historical or behavioral anomaly detection like impossible travel.

6
MCQeasy

A security team wants to automatically investigate and respond to security incidents across endpoints, email, and identities without manual intervention. Which Microsoft Defender XDR capability provides this automation?

A.Automated investigation and response (AIR)
B.Advanced hunting
C.Threat analytics
D.Attack surface reduction rules
AnswerA

Automated investigation and response (AIR) in Microsoft Defender XDR automatically investigates alerts across endpoints, email, and identities, then applies remediation actions without analyst input. This directly satisfies the stem's requirement for hands-off response spanning all three workloads, unlike standalone playbooks or manual triage.

Why this answer

Automated investigation and response (AIR) is the Microsoft Defender XDR capability that automatically investigates alerts and takes remediation actions across endpoints, email, and identities without manual intervention. It uses playbooks and machine learning to triage incidents, determine scope, and apply actions like isolating devices or deleting malicious emails.

Exam trap

The trap here is that candidates confuse 'automated investigation and response' with 'advanced hunting' because both involve security analysis, but only AIR provides the automated remediation workflow without manual querying.

How to eliminate wrong answers

Option B is wrong because advanced hunting is a query-based tool for manually searching raw telemetry data using Kusto Query Language (KQL), not an automated response mechanism. Option C is wrong because threat analytics provides threat intelligence reports and vulnerability assessments but does not perform automated investigation or response actions. Option D is wrong because attack surface reduction rules are endpoint-specific configurations that block common attack techniques (e.g., Office macro execution), but they do not automate the investigation and response lifecycle across multiple domains.

7
MCQhard

You are configuring Microsoft Defender for Office 365 anti-phish policy. You want to protect against user impersonation attacks. The CEO and CFO are frequent targets. What should you configure in the anti-phish policy?

A.Configure spoof intelligence
B.Add the CEO and CFO's domains to domain impersonation
C.Enable user impersonation protection and add the CEO and CFO as protected users
D.Enable mailbox intelligence
AnswerC

User impersonation protection compares the sender's display name and address against a defined list, so adding the CEO and CFO as protected users blocks spoofed messages impersonating those executives, directly meeting the stated targeting of frequent executive targets.

Why this answer

User impersonation protection in anti-phish policies allows you to add specific users (e.g., CEO and CFO) as protected users. This protects against attacks where an attacker impersonates those users. Option A is incorrect because spoof intelligence protects against domain spoofing, not user impersonation.

Option B is incorrect because domain impersonation protects against impersonation of entire domains, not individual users. Option D is incorrect because mailbox intelligence is a feature that learns user communication patterns to detect impersonation, but it is not the configuration to protect specific users.

8
MCQmedium

A user reports that they are unable to access a file in SharePoint Online. You check the audit log and see that the file was quarantined by Microsoft Defender for Office 365. What is the most likely reason?

A.The file was overwritten by a previous version.
B.The file was detected as malware by Safe Attachments.
C.The file has a retention policy that moved it to the Preservation Hold library.
D.The file was labeled as highly confidential by Microsoft Purview Information Protection.
E.The file contains sensitive information and triggered a Data Loss Prevention (DLP) policy.
AnswerB

Safe Attachments detonates email attachments in a sandbox before delivery, and files found malicious are quarantined. Since the stem confirms Microsoft Defender for Office 365 quarantined the SharePoint file, malware detection by Safe Attachments is the mechanism that satisfies this constraint.

Why this answer

Microsoft Defender for Office 365 uses Safe Attachments to detect and quarantine malicious files in SharePoint Online. Option A is wrong because overwriting by a previous version does not trigger quarantine. Option C is wrong because retention policies move files to Preservation Hold library, not quarantine.

Option D is wrong because sensitivity labels classify files but do not quarantine them. Option E is wrong because DLP policies block sharing or apply protections, but do not quarantine files.

9
MCQeasy

You run the above KQL query in Microsoft Defender XDR Advanced Hunting. The query returns no results. What is the most likely reason?

A.The EmailDirection filter should be 'Outbound'.
B.No inbound emails were blocked in the last 30 days.
C.The time range should be 7 days instead of 30 days.
D.The column name SenderDomain does not exist in EmailEvents.
AnswerD

EmailEvents in Microsoft 365 Defender Advanced Hunting does not contain a column named SenderDomain; the domain can be accessed through SenderMailFromDomain (envelope domain) or SenderFromDomain (display domain). Because the query references an invalid schema field, the entire query fails with a recognized column not found error before any rows can be processed. Using the correct domain column would allow the hunt to run.

Why this answer

The most likely reason is that the column name 'SenderDomain' does not exist in the EmailEvents table. In Microsoft Defender XDR Advanced Hunting, the EmailEvents table contains columns like 'SenderFromDomain' or 'SenderMailFromDomain', but not 'SenderDomain'. Therefore, the query would fail to return results because of an invalid column reference.

Exam trap

MS-102 often tests knowledge of the exact column names in Advanced Hunting tables, and candidates may assume a column exists based on common sense rather than verifying the schema.

How to eliminate wrong answers

Option A is wrong because the EmailDirection filter should be 'Inbound' for inbound emails; changing to 'Outbound' would not fix the issue if the query is about inbound emails. Option B is wrong because if no inbound emails were blocked, the query would return no results, but that is a possible reason, not the most likely; the question implies the query itself is flawed. Option C is wrong because the time range of 30 days is valid and would not cause no results unless there were no events, but again, the column name error is more fundamental.

10
MCQeasy

Your organization uses Microsoft Defender for Endpoint (MDE). You need to configure an automated investigation and response (AIR) capability that will automatically remediate a confirmed malware infection on endpoints. Which action should you enable?

A.Run antivirus scan
B.Notify users via email
C.Automatically resolve alerts
D.Isolate device
AnswerC

Enabling the 'Automatically resolve alerts' option instructs Defender for Endpoint's automated investigation engine to execute appropriate remediation actions and then close the alert when the investigation reaches a conclusion. This setting is the key to connecting determined threat severity with response steps, allowing alert incidents to be resolved without manual triage. It ensures that if remediation succeeds, the alert is automatically marked as resolved.

Why this answer

Enabling 'Automatically resolve alerts' in Microsoft Defender for Endpoint's automated investigation and response (AIR) capabilities allows the system to automatically remediate confirmed malware infections by resolving the alert and applying the appropriate remediation actions (e.g., quarantining files, terminating processes) without manual intervention. This setting ensures that once an investigation confirms a threat, the response is executed automatically, aligning with the requirement for automated remediation.

Exam trap

The trap here is that candidates often confuse enabling a specific remediation action (like 'Isolate device') with configuring the overall automated investigation and response capability, whereas the correct approach is to enable 'Automatically resolve alerts' which then triggers the appropriate remediation actions based on the investigation verdict.

How to eliminate wrong answers

Option A is wrong because 'Run antivirus scan' is a manual or scheduled action, not an automated response that triggers upon a confirmed malware infection; AIR uses pre-configured remediation actions, not on-demand scans. Option B is wrong because 'Notify users via email' is a notification action, not a remediation action; it informs users but does not automatically remediate the infection. Option D is wrong because 'Isolate device' is a specific remediation action that can be part of AIR, but enabling it alone does not configure the automated investigation and response capability; the correct setting to enable automatic remediation is 'Automatically resolve alerts', which then applies actions like isolation based on the investigation verdict.

11
MCQmedium

Your organization uses Microsoft Defender for Identity. You need to configure a honeytoken account to detect attackers trying to use the account. In which location should you place the honeytoken account?

A.A domain user account with no privileges
B.A service account with high privileges
C.A non-existent account alias in AD
D.A guest account
AnswerA

A domain user account with no privileges is the correct honeytoken because Microsoft Defender for Identity treats any authentication attempt using this account as suspicious. Since the account is a real Active Directory object, MDI can monitor and alert on its activity, and because it lacks any privileged group memberships or legitimate permissions, there is no valid reason for it to authenticate to any resource. This ensures that any authentication event involving the account is a high-confidence indicator of attacker activity, minimizing false positives while maximizing detection value.

Why this answer

A honeytoken account in Microsoft Defender for Identity is designed to lure attackers by appearing as a real, low-privilege account that no legitimate user should ever authenticate with. Placing it as a domain user account with no privileges ensures that any authentication attempt using its credentials is suspicious and triggers an alert, because no legitimate activity should involve this account. This allows Defender for Identity to detect lateral movement or credential theft attempts without risking exposure of sensitive resources.

Exam trap

The trap here is that candidates assume a honeytoken must have high privileges to be attractive to attackers, but Microsoft Defender for Identity specifically requires a low-privilege account that no legitimate user would ever use, so any authentication is automatically suspicious.

How to eliminate wrong answers

Option B is wrong because a service account with high privileges would be a legitimate target for attackers, and using it as a honeytoken could result in real privilege escalation if the account is compromised, defeating the purpose of a decoy. Option C is wrong because a non-existent account alias in AD cannot be used as a honeytoken; Defender for Identity requires an actual user object in Active Directory to monitor for authentication attempts. Option D is wrong because a guest account is typically disabled or has known usage patterns, and using it as a honeytoken would generate false positives from legitimate guest access or automated processes, reducing detection accuracy.

12
MCQhard

A security administrator needs to block outbound network connections from a compromised Windows device to command-and-control servers. The solution must work at the network layer and be centrally managed via Microsoft 365 Defender. Which feature should the administrator enable?

A.Network Protection
B.Attack Surface Reduction rules
C.Session control in Defender for Cloud Apps
D.Windows Firewall with Advanced Security
AnswerA

Network Protection in Microsoft Defender for Endpoint explicitly blocks outbound connections to malicious IP addresses, domains, and URLs using the Windows Filtering Platform. Unlike a static firewall rule, it dynamically enforces cloud-sourced threat intelligence, cutting off command-and-control traffic from a compromised device in real time. It is centrally configured and monitored through Microsoft 365 Defender, making it the correct tool for this network-layer containment scenario.

Why this answer

Network Protection in Microsoft Defender for Endpoint blocks outbound connections to command-and-control (C2) servers at the network layer by inspecting traffic using the Windows Filtering Platform (WFP). It is centrally managed via Microsoft 365 Defender policies and does not require per-device firewall rule configuration, making it the correct choice for this scenario.

Exam trap

The trap here is that candidates confuse 'network layer blocking' with Windows Firewall, but the question specifically requires a solution centrally managed via Microsoft 365 Defender, which Network Protection fulfills through the Defender for Endpoint security configuration.

How to eliminate wrong answers

Option B is wrong because Attack Surface Reduction (ASR) rules focus on blocking file-based and script-based attack techniques (e.g., Office macro execution, credential theft from LSASS), not network-layer outbound connections to C2 servers. Option C is wrong because Session control in Defender for Cloud Apps operates at the application layer (HTTP/S) via reverse proxy, not the network layer, and is designed for controlling access to cloud apps, not blocking C2 traffic from a compromised device. Option D is wrong because Windows Firewall with Advanced Security can block outbound connections but is not centrally managed via Microsoft 365 Defender; it requires Group Policy or PowerShell for centralized management, and it lacks the threat intelligence integration that Network Protection provides for dynamic C2 blocking.

13
Multi-Selecteasy

You are a security analyst. You need to investigate a potential malware outbreak on a device using Microsoft Defender XDR. Which three data sources can you include in an advanced hunting query to gather relevant information? (Choose three.)

Select 3 answers
A.CloudAppEvents
B.DeviceFileEvents
C.EmailAttachmentInfo
D.DeviceNetworkEvents
E.DeviceProcessEvents
AnswersB, D, E

DeviceFileEvents records file creation, modification and deletion activity on endpoints, so it surfaces the file writes and drops that malware typically performs. Including it in the advanced hunting query satisfies the requirement to gather device-level file telemetry alongside the other chosen sources.

Why this answer

DeviceFileEvents (B) is correct because it records file creation, modification, and other file-system activity on the endpoint, which is essential for tracing malware dropped or modified files during an outbreak. DeviceNetworkEvents (D) is correct because it captures network connections and related telemetry, allowing you to identify command-and-control traffic, lateral movement, or data exfiltration tied to the malware. DeviceProcessEvents (E) is correct because it logs process creation and execution details, letting you trace malicious process trees, parent-child relationships, and command lines used by the malware.

CloudAppEvents (A) is not among the marked answers because it covers cloud app and SaaS activity rather than endpoint malware artifacts, and EmailAttachmentInfo (C) is not marked because it concerns email attachment metadata, which is relevant to phishing delivery but not to the endpoint-focused advanced hunting sources selected here.

Exam trap

MS-102 often tests the distinction between device-centric and cloud/email-centric data sources — candidates may incorrectly include CloudAppEvents or EmailAttachmentInfo, which are not device-focused, when asked about malware on a device.

14
MCQmedium

You are a Microsoft 365 administrator. A user reports that they received a Microsoft Teams message from an external user containing a link to a malicious website. The user clicked the link but did not enter any credentials. You need to prevent similar incidents in the future. What should you configure?

A.Configure a Teams messaging policy to block all messages from external users.
B.Enable Safe Attachments for SharePoint, OneDrive, and Microsoft Teams.
C.Enable Safe Links for Microsoft Teams in Defender for Office 365.
D.Configure an anti-phishing policy to protect against impersonation in Teams.
AnswerC

Safe Links for Microsoft Teams rewrites and detonates URLs at click time, blocking malicious destinations even after delivery. This satisfies the stem's requirement to prevent future incidents, since the threat arrived via Teams chat rather than email, where Safe Links policies for Teams specifically apply.

Why this answer

Enabling Safe Links for Microsoft Teams in Defender for Office 365 provides time-of-click protection for links shared in Teams. Option A is wrong because blocking all external messages would hinder collaboration. Option B is wrong because Safe Attachments scans files, not links.

Option D is wrong because anti-phishing policies protect against impersonation, not malicious links.

15
MCQhard

A security analyst needs to identify the specific process (filename) that initiated a network connection from a device to a known malicious IP address over the last 24 hours. Which advanced hunting table in Microsoft Defender XDR provides the necessary data including the initiating process filename and the remote IP address?

A.DeviceNetworkEvents
B.DeviceProcessEvents
C.DeviceEvents
D.DeviceRegistryEvents
AnswerA

DeviceNetworkEvents is the Advanced Hunting table that records network connections observed on a device, with dedicated columns such as RemoteIP, RemotePort, LocalIP, LocalPort, Protocol, and the initiating process details (InitiatingProcessId, InitiatingProcessFileName). To identify the specific process that made a given network connection, an analyst can query this table and filter by the remote endpoint or timestamp, then read the initiating process information directly. This is the only table in the Advanced Hunting schema purpose-built for correlating process activity with network endpoints.

Why this answer

DeviceNetworkEvents is the correct table because it specifically captures network connection events, including the initiating process filename (InitiatingProcessFileName) and the remote IP address (RemoteIP). This table is designed for hunting network-related activities, such as connections to known malicious IPs, within Microsoft Defender XDR's advanced hunting schema.

Exam trap

The trap here is that candidates often confuse DeviceProcessEvents (which shows process creation) with network connection data, mistakenly thinking that process events include network details, but DeviceProcessEvents lacks the RemoteIP field entirely.

How to eliminate wrong answers

Option B (DeviceProcessEvents) is wrong because it focuses on process creation events (e.g., file execution, command-line arguments) and does not include network-specific fields like RemoteIP or remote port. Option C (DeviceEvents) is wrong because it aggregates various system-level events (e.g., file creation, registry modifications) but lacks the dedicated network connection fields required to identify the initiating process filename and remote IP address. Option D (DeviceRegistryEvents) is wrong because it only captures registry modification events (e.g., key changes, value writes) and has no relevance to network connections or IP addresses.

16
MCQmedium

A security analyst has identified a new malware sample with a specific SHA256 hash. The analyst needs to immediately block this file from executing on any managed endpoint across the organization, including prevention of future execution. Which Microsoft Defender for Endpoint capability should the analyst use?

A.Attack surface reduction (ASR) rules
B.Indicators (IoCs) for file hashes
C.Custom detection rules via advanced hunting
D.Microsoft Defender Vulnerability Management
AnswerB

File hash indicators are the correct solution because Microsoft Defender for Endpoint supports creating a file hash indicator with the action 'Block and Remediate,' which prevents the file from running and automatically removes matching files from protected devices. The indicator is honored by both the anti-malware engine and the behavior monitoring layer, so execution is stopped preemptively even before the process starts. This gives an immediate, global block across all onboarded endpoints.

Why this answer

Indicators of Compromise (IoCs) for file hashes in Microsoft Defender for Endpoint allow an analyst to create a block indicator for a specific SHA256 hash. This action immediately prevents the file from executing on any managed endpoint and persists across reboots, effectively blocking future execution attempts. Unlike other capabilities, IoCs provide a direct, hash-based block that is enforced by the Microsoft Defender Antivirus engine at the point of execution.

Exam trap

The trap here is that candidates often confuse ASR rules (which block behaviors) with IoC-based blocking (which blocks specific file hashes), or they assume custom detection rules can directly block execution when they only generate alerts or run limited response actions.

How to eliminate wrong answers

Option A is wrong because Attack Surface Reduction (ASR) rules are behavior-based policies that reduce the attack surface by blocking common malware behaviors (e.g., Office apps creating child processes), not by blocking specific file hashes. Option C is wrong because Custom detection rules via advanced hunting are used to create custom alerts based on query results, but they do not directly block file execution; they only trigger alerts or run response actions that may not be immediate or persistent. Option D is wrong because Microsoft Defender Vulnerability Management focuses on identifying, assessing, and remediating vulnerabilities (e.g., missing patches), not on blocking specific malware file hashes.

17
MCQmedium

A security administrator wants to configure Microsoft Defender for Cloud Apps to block downloads of sensitive files from Salesforce to unmanaged devices in real time. Which Defender for Cloud Apps component must be configured?

A.Cloud Discovery
B.App Connectors
C.Conditional Access App Control
D.Activity policies
AnswerC

Conditional Access App Control proxies sessions through Defender for Cloud Apps, enabling real-time inline enforcement such as blocking downloads to unmanaged devices. Session policies alone cannot block in real time, so this component satisfies the real-time blocking constraint for Salesforce.

Why this answer

Conditional Access App Control (CAAC) is the correct component because it enables real-time session-level monitoring and control of user activities in SaaS apps like Salesforce. By integrating with Azure AD Conditional Access, CAAC can enforce policies to block downloads of sensitive files to unmanaged devices at the moment of access, using reverse proxy architecture to inspect and intervene in the traffic.

Exam trap

The trap here is that candidates often confuse App Connectors (API-based governance) with Conditional Access App Control (proxy-based real-time control), assuming both can block downloads in real time, but only the reverse proxy can intercept and block actions during the session.

How to eliminate wrong answers

Option A is wrong because Cloud Discovery is used to identify shadow IT and analyze traffic logs to discover cloud apps in use, not to enforce real-time blocking policies on managed SaaS apps. Option B is wrong because App Connectors are used for API-based integration to scan and govern data at rest (e.g., applying DLP labels or quarantine), not for real-time session control of downloads. Option D is wrong because Activity policies are reactive, rule-based alerts triggered after an activity occurs (e.g., multiple failed logins), and cannot block actions in real time during the session.

18
MCQmedium

Your organization uses Microsoft Defender for Endpoint. You need to ensure that when a device is onboarded, it automatically receives all current threat intelligence signatures. What should you verify is configured?

A.The device is configured to receive updates from Microsoft Update.
B.Network protection is enabled in the attack surface reduction rules.
C.Sample submission is enabled in the advanced features.
D.Cloud-delivered protection is enabled in the Microsoft 365 Defender portal.
AnswerD

Cloud-delivered protection is the core mechanism connecting Microsoft Defender for Endpoint to Microsoft's cloud security intelligence. When enabled, the endpoint sends telemetry to the cloud and receives near-real-time responses, including newly generated signatures, 'block at first sight' decisions, and behavioral detections. This low-latency, dynamic channel is exactly what ensures the device gets real-time signature updates, beyond the static definitions delivered by Microsoft Update.

Why this answer

Cloud-delivered protection in the Microsoft 365 Defender portal ensures that devices receive the latest threat intelligence signatures in near real-time. When enabled, Defender for Endpoint uses the Microsoft Intelligent Security Graph to push updated signatures and machine learning models to onboarded devices automatically, without relying on manual update cycles.

Exam trap

The trap here is that candidates confuse cloud-delivered protection (which provides real-time signature updates) with other security features like network protection or sample submission, or assume that standard Microsoft Update handles Defender signatures.

How to eliminate wrong answers

Option A is wrong because Microsoft Update delivers Windows and Office updates, not Defender for Endpoint threat intelligence signatures; signature updates are managed through Windows Update for Defender or cloud-delivered protection. Option B is wrong because network protection is a component of attack surface reduction that blocks outbound connections to malicious IPs/domains, but it does not control the delivery of threat intelligence signatures. Option C is wrong because sample submission enables automatic file submission for analysis to improve detection, but it does not affect how current threat intelligence signatures are received by devices.

19
Multi-Selectmedium

Which TWO Microsoft Defender XDR components provide protection for email and collaboration tools? (Choose two.)

Select 2 answers
A.Microsoft Defender for Identity
B.Microsoft Defender for Office 365
C.Microsoft Defender for Cloud
D.Microsoft Defender for Cloud Apps
E.Microsoft Defender for Endpoint
AnswersB, D

Defender for Office 365 protects Exchange Online, SharePoint, OneDrive, and Microsoft Teams through features like anti-phishing, anti-spam, Safe Attachments, and Safe Links. It directly filters email traffic and inspects collaboration workloads for malicious content. This makes it the core email and collaboration protection component in Microsoft Defender XDR.

Why this answer

Microsoft Defender for Office 365 is the correct choice because it is the dedicated component that protects email and collaboration tools (Exchange Online, SharePoint Online, OneDrive for Business, and Teams) against threats like phishing, malware, and spam. It uses advanced machine learning and detonation analysis in Safe Attachments and Safe Links to inspect attachments and URLs in real time.

Exam trap

The trap here is that candidates often confuse Microsoft Defender for Cloud Apps (which provides cloud access security broker (CASB) controls for SaaS apps like Office 365) with direct email protection, but it is Defender for Office 365 that specifically handles email and collaboration threat protection, while Defender for Cloud Apps adds visibility and governance over sanctioned and unsanctioned cloud apps.

20
MCQmedium

Your organization has Microsoft Defender for Office 365. Users report that legitimate emails from a partner domain are being quarantined. You need to ensure these emails are delivered while maintaining security. What should you do?

A.Add the partner domain to the Allow list in the Tenant Allow/Block List.
B.Disable spam filtering for the partner domain.
C.Lower the spam confidence level (SCL) threshold for the organization.
D.Create a mail flow rule to bypass spam filtering for the partner domain.
AnswerA

Adding the partner domain to the Tenant Allow/Block List overrides the quarantine verdict for that sender, satisfying the requirement that legitimate partner mail be delivered. Entries here take precedence over filtering verdicts, so messages bypass quarantine while spoofing and malware protection remain active for all other senders.

Why this answer

The Tenant Allow/Block List in Microsoft Defender for Office 365 is the supported, granular mechanism for allowing specific senders or domains that are being incorrectly quarantined. Adding the partner domain as an allow entry tells Exchange Online Protection (EOP) to skip filtering actions (quarantine, junk, etc.) for messages from that domain while still applying other protections like malware scanning and Safe Links. This preserves security posture because only the specific false-positive source is exempted, not the entire filtering pipeline.

Exam trap

MS-102 often tests the misconception that a mail flow rule (transport rule) is the best way to bypass spam filtering, when in fact the Tenant Allow/Block List is the recommended, granular, and auditable method for allowing specific senders or domains.

How to eliminate wrong answers

Option B is wrong because disabling spam filtering for a domain is not a supported per-domain action in EOP; spam filtering is controlled by policies (anti-spam policies, connection filtering) that apply broadly, and turning it off would expose the tenant to all spam from that domain. Option C is wrong because lowering the SCL threshold organization-wide would make filtering more aggressive (or less, depending on direction) for all mail, not just the partner domain, and would not reliably fix a false positive while weakening overall protection. Option D is wrong because while a mail flow rule can set an SCL of -1 to bypass spam filtering, it is a blunt workaround that also bypasses other protections and is not the recommended, auditable method for allow-listing a domain; the Tenant Allow/Block List is the purpose-built control.

21
MCQeasy

Your organization uses Microsoft Defender XDR. You want to create a custom detection rule that triggers an alert when a specific process is created on multiple endpoints. Which advanced hunting table should you use?

A.DeviceNetworkEvents
B.DeviceFileEvents
C.DeviceLogonEvents
D.DeviceRegistryEvents
E.DeviceProcessEvents
AnswerE

DeviceProcessEvents records process creation events with process, command-line and device details across endpoints, so filtering on a specific process name triggers alerts when it appears on multiple devices. This matches the stem's requirement for process-creation detection across endpoints.

Why this answer

DeviceProcessEvents. This table captures process creation events, which is the required data for a detection rule on a specific process being created.

Option A (DeviceNetworkEvents) is incorrect because it logs network connections, not process creation.

Option B (DeviceFileEvents) is incorrect because it logs file operations.

Option C (DeviceLogonEvents) is incorrect because it logs logon events.

Option D (DeviceRegistryEvents) is incorrect because it logs registry changes.

22
MCQhard

You are designing an incident response plan using Microsoft Defender XDR. You want to automate the containment of compromised devices when a high-severity incident is detected. What should you configure?

A.Configure custom detection rules in Microsoft Defender for Endpoint
B.Configure device groups in Microsoft Defender for Endpoint
C.Enable automated investigation and response (AIR) in Microsoft Defender XDR
D.Create a playbook in Microsoft Sentinel
AnswerC

AIR can automatically contain devices based on incident severity.

Why this answer

C is correct because automated investigation and response (AIR) in Microsoft Defender XDR can automatically contain devices when a high-severity incident is detected. A is incorrect because custom detection rules in Microsoft Defender for Endpoint only create alerts; they do not automatically contain devices. B is incorrect because device groups are used for management and policy assignment, not for automated containment.

D is incorrect because playbooks in Microsoft Sentinel require manual triggering or other automation; they are not configured within Defender XDR.

23
MCQeasy

Your organization uses Microsoft Defender for Cloud Apps. You need to create a policy that automatically alerts when a user downloads more than 100 files from SharePoint Online in 10 minutes. What type of policy should you create?

A.Session policy
B.App discovery policy
C.Anomaly detection policy
D.OAuth app policy
AnswerC

Anomaly detection policies detect unusual file download activity.

Why this answer

An anomaly detection policy in Microsoft Defender for Cloud Apps is designed to identify unusual user behavior, such as a user downloading over 100 files from SharePoint Online within 10 minutes. This policy type uses machine learning and predefined thresholds to detect deviations from baseline activity, making it the correct choice for this scenario.

Exam trap

The trap here is that candidates often confuse anomaly detection policies with session policies, mistakenly thinking session policies can alert on cumulative activity, when in fact session policies only enforce real-time controls during an active session.

How to eliminate wrong answers

Option A is wrong because a session policy controls real-time user actions during a session (e.g., blocking downloads or requiring MFA) but does not automatically alert based on aggregate file download counts over time. Option B is wrong because an app discovery policy identifies shadow IT by analyzing traffic logs to discover cloud apps in use, not user-specific download behavior in SharePoint Online. Option D is wrong because an OAuth app policy governs permissions granted to third-party OAuth apps, not user file download activities.

24
Multi-Selectmedium

A security analyst wants to create a custom detection rule in Microsoft Defender XDR that triggers when a user receives a phishing email (delivered to inbox) and later clicks a link from that email that leads to a known malicious domain. The rule will be based on an advanced hunting query. Which two tables should the analyst join in the query to capture both the email delivery event and the link click event? (Choose two.)

Select 2 answers
A.EmailEvents
B.UrlClickEvents
C.DeviceEvents
D.IdentityLogonEvents
AnswersA, B

EmailEvents records the delivery outcome of each message, including whether it reached the inbox, satisfying the phishing-delivery half of the correlation. Joining it to UrlClickEvents on the NetworkMessageId links that delivered message to the subsequent click on the malicious URL, giving the advanced hunting query both required events.

Why this answer

EmailEvents contains records of email delivery events, including phishing emails that were delivered to the inbox. UrlClickEvents captures user clicks on URLs in emails, including the target domain. Joining these two tables on the email's network message ID allows the analyst to correlate the specific phishing email delivery with the subsequent link click to a known malicious domain, which is the exact scenario described.

Exam trap

The trap here is that candidates may confuse UrlClickEvents with DeviceEvents, thinking that a link click is a device-level action, but in Microsoft Defender XDR, URL clicks from emails are specifically tracked in the UrlClickEvents table, not in endpoint event tables.

25
MCQeasy

A security analyst identifies a malicious file hash on one endpoint. They need to ensure that file is blocked from executing on all other endpoints in the organization immediately. Which Microsoft Defender for Endpoint feature should be used?

A.Indicators of compromise (IOCs)
B.Attack surface reduction rules
C.Automated investigation and response
D.Custom detection rules
AnswerA

Indicators of compromise let analysts submit a file hash as a custom indicator, and Defender for Endpoint enforces block or allow actions across all onboarded endpoints. This satisfies the requirement to block the file organisation-wide immediately.

Why this answer

Indicators of compromise (IOCs) in Microsoft Defender for Endpoint allow security analysts to create custom indicators (e.g., file hashes, IPs, URLs) that are enforced across all endpoints in near real-time. By adding the malicious file hash as an IOC with an 'Alert and Block' action, the file is immediately prevented from executing on any managed device, providing a rapid, organization-wide block without waiting for signature updates.

Exam trap

The trap here is that candidates confuse 'Indicators of compromise (IOCs)' with 'Custom detection rules,' because both involve custom definitions, but IOCs are for immediate blocking of known artifacts while custom detection rules are for behavioral detection over time.

How to eliminate wrong answers

Option B is wrong because Attack surface reduction rules are pre-configured policies that reduce common attack vectors (e.g., blocking Office apps from creating child processes), but they cannot block a specific file hash on demand. Option C is wrong because Automated investigation and response (AIR) automatically investigates and remediates alerts after detection, but it does not proactively block a known malicious hash from executing; it reacts to incidents already triggered. Option D is wrong because Custom detection rules use Advanced Hunting queries to detect suspicious behavior over time, but they are not designed for immediate, hash-based execution blocking across all endpoints.

26
MCQhard

An organization wants to allow only specific company-approved USB devices (e.g., those with a specific hardware ID) on managed Windows devices. All other USB devices must be blocked. Which Microsoft 365 Defender feature should be configured?

A.Attack surface reduction rules
B.Microsoft Defender for Endpoint device control
C.Microsoft Defender for Cloud Apps session policy
D.Conditional Access device compliance
AnswerB

Microsoft Defender for Endpoint device control is the correct capability because it is purpose-built to enforce flexible policies on peripheral devices, especially USB storage. Device control policies define rules based on device instance IDs, hardware IDs, or device classes, and support actions such as allow, deny, or audit. This allows an administrator to create a policy that permits only company-approved USB devices (matched by their hardware IDs) while blocking all other USB devices, meeting the stated requirement directly.

Why this answer

Microsoft Defender for Endpoint device control is the correct feature because it provides granular control over peripheral devices, including USB devices, based on hardware IDs. It allows administrators to create allow/block policies that enforce restrictions on managed Windows devices, ensuring only company-approved USB devices can be used.

Exam trap

The trap here is that candidates often confuse Attack surface reduction rules with device control because both are part of Microsoft Defender for Endpoint, but ASR rules focus on process behaviors, not hardware device access.

How to eliminate wrong answers

Option A is wrong because Attack surface reduction rules are designed to mitigate common malware behaviors (e.g., blocking Office apps from creating child processes) and do not include USB device control capabilities. Option C is wrong because Microsoft Defender for Cloud Apps session policies are used to monitor and control user sessions in cloud apps (e.g., blocking downloads from SharePoint) and have no effect on local USB device access. Option D is wrong because Conditional Access device compliance policies evaluate device health (e.g., requiring BitLocker or antivirus) for cloud app access but do not enforce USB device restrictions on the endpoint itself.

27
MCQmedium

You are a security administrator for a company that uses Microsoft 365 E5. The security team wants to automatically block malicious files and URLs in email attachments and links based on Microsoft's threat intelligence, without manual intervention. You need to configure this in Microsoft Defender for Office 365. What should you do?

A.Enable Safe Attachments and Safe Links policies with the 'Block' action.
B.Set up a Data Loss Prevention (DLP) policy to block emails containing sensitive information.
C.Configure an Exchange Online mail flow rule to reject messages with attachments.
D.Create a transport rule to prepend a warning banner to external emails.
AnswerA

Safe Attachments and Safe Links with Block action automatically block malicious content based on real-time threat intelligence. Safe Attachments detonates attachments in a sandbox, and Safe Links checks URLs at time of click, blocking access if malicious. This provides automatic protection without manual intervention, directly meeting the requirement.

Why this answer

Safe Attachments and Safe Links are Microsoft Defender for Office 365 features that use Microsoft's threat intelligence to automatically block malicious attachments and URLs. They provide real-time protection without manual intervention, aligning with the requirement to automatically block based on threat intelligence.

Exam trap

The trap here is assuming that any email filtering rule can block malicious content, but only Safe Attachments and Safe Links leverage threat intelligence for automatic blocking.

28
MCQmedium

You are a Microsoft 365 administrator for Contoso, Ltd. The security team uses Microsoft Defender XDR. They want to be alerted when a user's Microsoft Entra ID account is disabled but the user still has an active session on a device. You need to configure a custom detection rule that triggers on this condition. Which data source and query approach should you use?

A.Use the IdentityDirectoryEvents table in Microsoft Defender XDR advanced hunting with a query that filters for 'AccountDisabled' actions and joins with DeviceLogonEvents.
B.Use the AlertInfo table and filter for alerts with a severity of 'High' and a category of 'Credential Access'.
C.Use the CloudAppEvents table and filter for 'DisableAccount' operations performed by an administrator.
D.Use the DeviceEvents table in Microsoft Defender for Endpoint with a query that filters for 'UserAccountDisabled' actions.
AnswerA

IdentityDirectoryEvents captures directory-level changes, including account disablement, from Microsoft Defender for Identity. By joining with DeviceLogonEvents, you can correlate the disabled account with active sessions on devices. This combination directly addresses the scenario's requirement to detect when a disabled user still has an active device session, making it the correct approach for the custom detection rule.

Why this answer

The requirement is to detect a disabled Microsoft Entra ID account that still has an active device session. IdentityDirectoryEvents in Microsoft Defender XDR advanced hunting records directory changes such as account disabling, and DeviceLogonEvents tracks logon activity on devices. Joining these tables allows you to identify sessions that remain active after the account is disabled.

Other tables lack either the identity event or the device session context, so they cannot satisfy the scenario.

Exam trap

The trap here is assuming that endpoint event tables like DeviceEvents contain identity-related actions, when account disablement is actually captured in identity-focused tables such as IdentityDirectoryEvents.

29
MCQhard

Refer to the exhibit. You run the KQL query in advanced hunting. What is the primary purpose of this query?

A.Identify devices with outbound connections to malicious IPs
B.Identify devices with PowerShell execution policy set to bypass
C.Identify devices where a user deleted system files using cmd
D.Identify devices with high use of encoded commands, which may indicate malicious activity
AnswerD

The query aggregates encoded command usage per device, so its purpose is surfacing endpoints whose PowerShell or shell activity is heavily encoded. High encoded-command counts frequently indicate obfuscated malicious execution, making this a threat-hunting signal rather than a compliance or inventory check.

Why this answer

The KQL query filters for DeviceProcessEvents where the command line contains 'powershell' and the process command line includes '-EncodedCommand', which is a known technique used by attackers to obfuscate malicious scripts. The query then counts such events per device and filters for devices with more than 10 occurrences, indicating a high volume of encoded PowerShell commands that may signal malicious activity.

Exam trap

The trap here is that candidates may confuse 'encoded commands' with 'execution policy bypass' or focus on the presence of PowerShell without recognizing that the specific '-EncodedCommand' parameter is the key indicator of obfuscation and potential malicious activity.

How to eliminate wrong answers

Option A is wrong because the query does not reference any network events (e.g., DeviceNetworkEvents) or IP addresses; it only examines process command lines. Option B is wrong because the query does not check for PowerShell execution policy settings (e.g., 'Set-ExecutionPolicy Bypass'); it focuses on encoded commands, not policy configurations. Option C is wrong because the query does not look for 'cmd' or deletion of system files; it specifically targets PowerShell with '-EncodedCommand', not cmd.exe or file deletion events.

30
Multi-Selectmedium

Your organization uses Microsoft Defender XDR. You are configuring a custom detection rule to detect a specific behavior: a user runs a PowerShell script that connects to a known malicious IP address. Which TWO advanced hunting tables should you use in your KQL query to detect this behavior?

Select 2 answers
A.DeviceProcessEvents
B.DeviceRegistryEvents
C.DeviceLogonEvents
D.DeviceFileEvents
E.DeviceNetworkEvents
AnswersA, E

DeviceProcessEvents captures process creation, including PowerShell command lines, satisfying the requirement to detect script execution. However, it does not record network connections, so pairing it with DeviceNetworkEvents is necessary to identify the connection to the known malicious IP address.

Why this answer

To detect a user running a PowerShell script that connects to a known malicious IP address, you need to correlate process creation events (to capture the PowerShell script execution) with network connection events (to capture the outbound connection to the IP address). DeviceProcessEvents tracks process creation, including PowerShell.exe. DeviceNetworkEvents tracks network connections to remote IP addresses.

Therefore, the correct tables are DeviceProcessEvents (A) and DeviceNetworkEvents (E).

31
MCQeasy

Your organization uses Microsoft Defender for Cloud Apps. You need to be alerted when a user accesses a cloud app from an anonymous IP address. Which type of policy should you create?

A.Session policy
B.File policy
C.Activity policy
D.App discovery policy
AnswerC

Activity policies in Microsoft Defender for Cloud Apps inspect user activity events and raise alerts on matching conditions. Configuring one with an anonymous IP filter detects access from anonymising proxies or Tor, satisfying the stem's requirement to alert on anonymous IP access.

Why this answer

An activity policy in Microsoft Defender for Cloud Apps can detect access from anonymous IP addresses by monitoring user activities. Option A is incorrect because a session policy controls user sessions in real-time but does not specifically alert on anonymous IP access. Option B is incorrect because a file policy focuses on monitoring and protecting files, not on access from anonymous IPs.

Option D is incorrect because an app discovery policy is used to discover shadow IT and unsanctioned apps, not to alert on anonymous IP access.

32
MCQeasy

You are a Microsoft 365 administrator for Tailspin Toys. The security team wants to reduce the number of alerts generated by Microsoft Defender for Endpoint on Windows 10 devices that run a custom line-of-business application. The application performs many legitimate network connections that trigger the 'Suspicious network connection' alert. You need to suppress these alerts while still investigating all other alerts. What should you create in the Microsoft 365 Defender portal?

A.An automated investigation and response (AIR) playbook that closes the alert automatically.
B.An alert suppression rule for the 'Suspicious network connection' alert scoped to the affected devices or application.
C.An indicator of compromise (IoC) for the application's executable hash with the action Allow.
D.A custom detection rule that queries DeviceNetworkEvents and marks the connections as benign.
AnswerB

Alert suppression rules in Microsoft Defender for Endpoint let you suppress specific alerts for defined scopes, such as a device group, file hash, IP address, or URL. Scoping the rule to the custom application and the affected devices stops the noisy alert while leaving all other detections active, which matches the requirement to keep investigating other alerts.

Why this answer

Alert suppression rules in Microsoft Defender for Endpoint are designed to reduce alert noise by suppressing specific alerts within a defined scope, such as a device group, file hash, IP address, or URL. Scoping the rule to the line-of-business application and its devices silences the known false positive while preserving visibility into all other alerts. Indicators of compromise change block or allow behavior, and AIR or custom detections act after or alongside alerts rather than suppressing them.

Exam trap

The trap here is confusing an allow indicator of compromise with alert suppression, when an allow IoC changes blocking behavior but does not stop behavioral alerts from being generated.

33
MCQmedium

Your organization has Microsoft Defender for Office 365 Plan 2. You need to ensure that when a user reports a phishing email using the Report Message add-in, the email is automatically submitted to Microsoft for analysis and the user is notified of the result. What should you configure?

A.Create a Safe Links policy to block the reported email
B.Configure an anti-phishing policy to automatically submit reported emails
C.Use a mail flow rule to send reported emails to a custom mailbox
D.Configure a submission policy in the Microsoft 365 Defender portal
AnswerD

A submission policy in the Microsoft 365 Defender portal defines how user-reported messages are handled, including automatic submission to Microsoft for analysis and configuring notifications back to the reporting user. This directly satisfies the requirement to submit reported phishing emails and notify users of the verdict.

Why this answer

In Microsoft 365 Defender, user-reported messages are handled through the Submissions page, governed by a user submission policy. Configuring this policy in the Defender portal lets you route reported phish to Microsoft for analysis, set the user-reported mailbox, and enable result notifications back to the reporting user. This is the native mechanism for the Report Message/Report Phishing add-ins.

Exam trap

MS-102 often tests the misconception that anti-phishing or Safe Links policies handle user-reported messages; candidates pick those because they sound security-related, missing that submissions are governed by a dedicated submission policy.

How to eliminate wrong answers

Option A is wrong because Safe Links rewrites and detonates URLs at click time; it does not process user-reported messages or notify reporters. Option B is wrong because anti-phishing policies define impersonation and spoof intelligence thresholds, not the user-reporting submission workflow. Option C is wrong because a mail flow (transport) rule can redirect mail to a mailbox but does not submit to Microsoft for analysis or generate user notifications.

34
MCQhard

A security administrator needs to block executable files (e.g., .exe, .ps1) from running from the %TEMP% folder on Windows devices to prevent common malware execution. Which attack surface reduction (ASR) rule should be enabled?

A.Block executable files from running unless they meet a prevalence, age, or trusted list criterion
B.Block executable content from email client and webmail
C.Block Office applications from creating child processes
D.Block credential stealing from the Windows local security authority subsystem (lsass.exe)
AnswerA

This ASR rule blocks executables from running in common writable folders, including %TEMP%, unless the executable is prevalent, old enough, or on an allowlist. It uses cloud-based reputation to evaluate the file's prevalence and age, allowing trusted files while blocking unknown or untrusted ones. Since the scenario requires blocking .exe and .ps1 files from launching in the temporary folder, this reputation-based filter is the correct mitigation.

Why this answer

ASR rule 'Block executable files from running unless they meet a prevalence, age, or trusted list criterion' (GUID: 01443614-cd74-433a-b99e-2ecdc07bfc25) is designed specifically to block executables (including .exe, .ps1, .scr, .dll) from launching from locations like %TEMP%, %APPDATA%, and the Windows folder, which are common malware staging areas. This rule uses cloud-delivered reputation (prevalence and age) and a Microsoft-managed trusted list to allow legitimate files while blocking unknown or suspicious ones, directly addressing the requirement to prevent malware execution from %TEMP%.

Exam trap

The trap here is that candidates confuse ASR rules by their generic names — they might pick 'Block executable content from email client and webmail' because it mentions 'executable content,' but the question specifically targets execution from the %TEMP% folder, not email delivery.

How to eliminate wrong answers

Option B is wrong because 'Block executable content from email client and webmail' targets executable attachments and scripts in email/webmail clients (e.g., Outlook, Gmail) to prevent phishing-based malware delivery, not execution from local folders like %TEMP%. Option C is wrong because 'Block Office applications from creating child processes' prevents Office apps (Word, Excel, etc.) from spawning child processes (e.g., cmd.exe, powershell.exe), which stops macro-based attacks but does not restrict executables already in %TEMP%. Option D is wrong because 'Block credential stealing from the Windows local security authority subsystem (lsass.exe)' specifically protects LSASS memory from being dumped or accessed by tools like Mimikatz, addressing credential theft, not executable execution from %TEMP%.

35
MCQmedium

A security team wants to automatically investigate and remediate alerts generated from Microsoft Defender for Endpoint, Office 365, and Microsoft Entra ID. Which Microsoft Defender XDR capability should be configured?

A.Threat Analytics
B.Automated Investigation and Response
C.Advanced Hunting
D.Secure Score
AnswerB

Automated Investigation and Response (AIR) in Microsoft 365 Defender orchestrates security playbooks across endpoints, email, and identity signals, automatically collecting evidence, initiating investigations, and executing remediation actions such as quarantining files, suspending accounts, and blocking URLs. AIR leverages AI and predefined automation rules to contain low-impact threats in real time, with optional human approval for destructive actions.

Why this answer

Automated Investigation and Response (AIR) in Microsoft Defender XDR is the correct capability because it automatically triggers playbooks to investigate and remediate alerts across Microsoft Defender for Endpoint, Office 365, and Microsoft Entra ID. AIR uses predefined or custom automation rules to correlate signals from these sources, run investigations, and apply remediation actions like isolating devices or blocking accounts without manual intervention.

Exam trap

The trap here is that candidates often confuse Threat Analytics (which provides threat intelligence) with Automated Investigation and Response (which executes automated remediation), leading them to select A when the question explicitly asks for a capability that 'automatically investigates and remediates' alerts.

How to eliminate wrong answers

Option A is wrong because Threat Analytics is a reporting and intelligence feature that provides threat actor profiles, attack techniques, and recommended mitigations, but it does not perform automated investigation or remediation actions. Option C is wrong because Advanced Hunting is a query-based tool using Kusto Query Language (KQL) to manually search for threats across raw data tables, not an automated response mechanism. Option D is wrong because Secure Score is a security posture measurement tool that tracks configuration improvements and recommendations, not a capability for investigating or responding to active alerts.

36
MCQhard

You are investigating a potential security incident in Microsoft Defender XDR. The incident involves a user who received a phishing email and clicked a link that executed a PowerShell script. You need to perform a detailed investigation of the PowerShell script's behavior across all affected devices. Which feature should you use?

A.Advanced hunting in Microsoft Defender XDR.
B.The Action Center in Microsoft Defender XDR.
C.Live Response from Microsoft Defender for Endpoint.
D.The device timeline in the Microsoft 365 Defender portal.
AnswerA

Advanced hunting in Microsoft Defender XDR is a KQL-based query tool that gives you access to raw telemetry stored in a structured schema, including tables such as DeviceProcessEvents, DeviceNetworkEvents, and EmailAttachmentInfo. You can run a query on a suspicious script hash, process name, or command line to identify every endpoint and mailbox where that script may have appeared, enabling cross-domain threat hunting. This direct access to historical, correlated data makes it the correct choice for a cross-device investigation.

Why this answer

Advanced hunting in Microsoft Defender XDR allows you to run KQL queries across all affected devices, enabling detailed investigation of the PowerShell script's behavior. It provides access to raw event data from multiple sources, including device process events, network connections, and file operations, which are essential for understanding script execution and impact.

Exam trap

MS-102 often tests the distinction between advanced hunting (proactive, cross-device querying) and live response (reactive, single-device remediation), causing candidates to confuse investigation with remediation.

How to eliminate wrong answers

Option B is wrong because the Action Center is used to manage remediation actions, not for proactive investigation. Option C is wrong because Live Response is designed for remote interactive remediation on a single device, not for querying across all affected devices. Option D is wrong because the device timeline shows events for a single device, not across all devices, and lacks the query flexibility of advanced hunting.

37
MCQeasy

You are configuring Microsoft Defender for Identity to monitor on-premises Active Directory. You need to ensure that honeytoken accounts are configured to detect attackers attempting to use them. What is a honeytoken account?

A.A service account used for application authentication
B.A disabled user account that cannot be used for sign-in
C.A fake user account created to attract attackers
D.A real user account with high privileges used for monitoring
AnswerC

A honeytoken account is a decoy identity with no legitimate purpose, so any authentication attempt against it signals malicious reconnaissance or credential misuse. Defender for Identity alerts on such activity, exposing attackers probing Active Directory without generating false positives from real users.

Why this answer

A honeytoken account is a fake user account created to lure attackers. When an attacker tries to use it, Defender for Identity triggers an alert. Option A is incorrect because honeytoken accounts are not real service accounts.

Option B is incorrect because they are not necessarily disabled; they can be enabled but with no real privileges. Option D is incorrect because they are not real high-privilege accounts, but fake decoys.

38
MCQmedium

You are configuring Microsoft Defender for Identity (MDI) to monitor for lateral movement attacks. Which of the following activities would MDI alert on as a potential lateral movement?

A.A user logging into multiple servers using a compromised account.
B.A user performing a DCSync attack.
C.A user conducting a password spray attack.
D.A user executing a privilege escalation tool on their workstation.
E.A user performing a brute force attack on a domain controller.
AnswerA

Logging into multiple servers with one compromised account is classic lateral movement; Microsoft Defender for Identity detects this via its account reconnaissance and lateral movement detections, correlating authentication events across domain controllers to flag abnormal spread that satisfies the monitoring scenario.

Why this answer

Microsoft Defender for Identity (MDI) can detect lateral movement when a compromised account is used to log into multiple servers, which indicates an attacker moving laterally within the network. Option B is incorrect because DCSync is a domain replication attack that targets the domain controller to extract credentials, not lateral movement. Option C is incorrect because password spray is a type of brute force attack that tries common passwords against many accounts, not lateral movement.

Option D is incorrect because executing a privilege escalation tool on a workstation is a local privilege escalation attempt, not lateral movement between systems. Option E is incorrect because brute force attacks on a domain controller are authentication attacks, not lateral movement.

39
Multi-Selectmedium

Which TWO actions can you perform using Microsoft Defender XDR's Advanced Hunting? (Choose two.)

Select 2 answers
A.Deploy EDR sensors to endpoints.
B.Configure data retention policies for logs.
C.Create custom detection rules based on query results.
D.Manage the status of incidents.
E.Run KQL queries to hunt for threats across email, endpoints, identities, and apps.
AnswersC, E

Advanced Hunting's Kusto Query Language results can be saved as custom detection rules, which run on a schedule and trigger alerts or automated response actions. This satisfies the stem's requirement for an action available directly within Microsoft Defender XDR, rather than relying on a separate portal or service.

Why this answer

Advanced Hunting in Microsoft Defender XDR allows you to run KQL queries across data from various Defender services, so option E is correct. You can also create custom detection rules based on query results, making option C correct. Option A (deploy EDR sensors) is done via group policy or Intune, not in Advanced Hunting.

Option B (configure data retention) is a tenant-level setting. Option D (manage incident status) is performed in the Incidents queue, not in Advanced Hunting.

40
MCQmedium

An organization uses Microsoft Defender for Cloud Apps to monitor shadow IT. They want to enforce policies that block downloads from risky cloud apps. Which Microsoft Defender XDR component provides this capability?

A.Microsoft Defender for Cloud Apps
B.Microsoft Defender for Endpoint
C.Microsoft Defender for Identity
D.Microsoft Defender for Office 365
AnswerA

Microsoft Defender for Cloud Apps is a Cloud Access Security Broker (CASB) that discovers sanctioned and unsanctioned cloud apps, assesses risk via the Cloud App Catalog, and enforces real-time session and access policies. It can restrict risky app usage using conditional access app controls, block downloads, or apply DLP checks across thousands of third-party SaaS services — capabilities no workload-specific Defender product can provide.

Why this answer

Microsoft Defender for Cloud Apps is the correct component because it is specifically designed to provide visibility into shadow IT and enforce policies on cloud applications. Its 'Governance' actions include blocking downloads from risky apps by integrating with the cloud app's API to prevent data exfiltration, which directly addresses the requirement.

Exam trap

The trap here is that candidates often confuse Microsoft Defender for Cloud Apps with Microsoft Defender for Office 365, assuming that Office 365's data loss prevention (DLP) covers all cloud apps, but DLP in Office 365 is limited to Microsoft 365 services, not third-party shadow IT apps.

How to eliminate wrong answers

Option B is wrong because Microsoft Defender for Endpoint focuses on endpoint detection and response (EDR), antivirus, and vulnerability management on devices, not on controlling downloads from cloud apps. Option C is wrong because Microsoft Defender for Identity monitors on-premises Active Directory for identity-based attacks (e.g., lateral movement, privilege escalation) and does not manage cloud app policies. Option D is wrong because Microsoft Defender for Office 365 protects email and collaboration tools (Exchange Online, SharePoint, Teams) from threats like phishing and malware, but it does not enforce download blocks across a broad set of cloud apps discovered via shadow IT.

41
MCQmedium

Your organization uses Microsoft Defender XDR and Microsoft 365 E5 licenses. You need to ensure that when a user reports a phishing email using the Microsoft Report Message add-in, the email is automatically submitted to Microsoft for analysis and the user is notified of the analysis result. You want to minimize administrative effort. What should you do?

A.Create a mail flow rule that forwards reported messages to a security team mailbox.
B.Configure the Microsoft Report Message add-in for all users.
C.Use the Microsoft 365 Defender portal to manually submit the email for analysis whenever a user reports it.
D.In Microsoft Defender XDR, go to Settings > Email & collaboration > User reported messages, and enable 'Send reported messages to Microsoft' and 'Notify users when analysis completes'.
AnswerD

Enabling 'Send reported messages to Microsoft' and 'Notify users when analysis completes' in the User reported messages settings routes reports automatically and returns verdicts to users, satisfying the minimal administrative effort constraint without custom flows or policies.

Why this answer

The user-reported messages settings in Microsoft Defender XDR (Settings > Email & collaboration > User reported messages) allow you to automatically send reported messages to Microsoft for analysis and notify users when analysis completes, minimizing administrative effort. Option A is wrong because a mail flow rule would only forward messages to a security team mailbox, not to Microsoft, and would not provide automatic analysis or user notification. Option B is wrong because simply configuring the Report Message add-in for all users enables reporting but does not by itself automatically submit to Microsoft or notify users; the Defender XDR settings are required for those actions.

Option C is wrong because manually submitting each reported email via the Microsoft 365 Defender portal defeats the goal of minimizing administrative effort and does not automatically notify the user of results.

42
MCQmedium

A company is experiencing a significant number of phishing attempts that target high-level executives by impersonating their email addresses. The security team wants to configure protection against user impersonation in Microsoft Defender for Office 365. Which setting must be enabled in the anti-phishing policy to protect these specific users?

A.Enable users to protect against impersonation
B.Enable domains to protect against impersonation
C.Mailbox intelligence
D.Spoofed sender posture
AnswerA

This setting allows you to define a list of specific users (e.g., executives) whose email addresses are protected from being impersonated in inbound emails. When impersonation is detected, the action defined in the policy is applied.

Why this answer

The 'Enable users to protect against impersonation' setting in an anti-phishing policy allows you to specify a list of users (such as high-level executives) whose email identities will be monitored for impersonation attempts. When enabled, Defender for Office 365 analyzes inbound messages for display name and email address matches against the protected users, and if a match is found with a suspicious sender, the message is flagged or quarantined. This directly addresses the scenario of attackers spoofing executive email addresses.

Exam trap

The trap here is that candidates often confuse 'user impersonation protection' with 'domain impersonation protection' or 'spoof intelligence,' but the question specifically asks for protection against impersonation of individual users, which requires the user-based setting, not domain-level or spoof-based controls.

How to eliminate wrong answers

Option B is wrong because 'Enable domains to protect against impersonation' protects against impersonation of entire domains (e.g., contoso.com), not specific individual user mailboxes, so it would not target the high-level executives as individuals. Option C is wrong because 'Mailbox intelligence' is a feature that learns normal sending patterns for users in your organization to detect anomalies, but it does not provide a static list of protected users; it relies on behavioral baselines rather than explicit user protection. Option D is wrong because 'Spoofed sender posture' is part of the spoof intelligence feature that evaluates the authentication status of the sending domain (SPF, DKIM, DMARC), not the impersonation of a specific user's display name or email address.

43
MCQmedium

Your organization uses Microsoft Defender for Identity. You receive an alert about a potential DCSync attack. What should you do to investigate this alert in Microsoft Defender XDR?

A.Review the IdentityDirectoryEvents table for replication-related events.
B.Use IdentityQueryEvents to find LDAP queries related to replication.
C.Check the IdentityAlertEvents table to see if the alert has additional context.
D.Run a KQL query in Advanced Hunting against IdentityLogonEvents to identify suspicious replication attempts.
AnswerD

IdentityLogonEvents is the correct table because it records authentication and logon events, including those that occur when an account attempts to replicate domain data via DRSUAPI. During a DCSync attack, the attacker's replication request appears as a logon event with specific attributes, such as a particular logon type or the use of replication privileges. Running a KQL query against IdentityLogonEvents allows you to filter for these suspicious patterns, such as account names, source IPs, and timing, making it the proper source for identifying replication attempts in Advanced Hunting.

Why this answer

DCSync attacks are performed by requesting domain replication via the MS-DRSR protocol, which generates specific directory replication events. In Microsoft Defender XDR, these replication attempts are logged in the IdentityLogonEvents table when an account authenticates to a domain controller for replication purposes. Running a KQL query against this table allows you to identify the source account, target domain controller, and the specific replication activity that triggered the alert.

Exam trap

The trap here is that candidates confuse the different Advanced Hunting tables: they assume DCSync is an LDAP query (Option B) or a directory object change (Option A), when in fact it is a replication protocol event logged in IdentityLogonEvents.

How to eliminate wrong answers

Option A is wrong because the IdentityDirectoryEvents table captures changes to directory objects (e.g., modifications, creations), not the replication protocol events that indicate a DCSync attack. Option B is wrong because IdentityQueryEvents logs LDAP queries, but DCSync uses the MS-DRSR replication protocol (not LDAP) to request replication of password hashes. Option C is wrong because while IdentityAlertEvents contains alert metadata, it does not contain the raw replication event data needed to investigate the specific replication attempt; you need to query the underlying event tables.

44
MCQhard

A security administrator wants to configure Microsoft Defender for Cloud Apps so that when a user accesses a sensitive file in a sanctioned cloud app from an unmanaged device, the user is blocked from downloading the file and a block action is logged in real time. Which type of policy should the administrator configure?

A.Create a session policy with the action 'Block' on the download action for files with a specific sensitivity label
B.Create a file policy that monitors for sensitive files being accessed from unmanaged devices and generates an alert
C.Configure an access policy that blocks access to the cloud app from unmanaged devices
D.Configure an activity policy that monitors download activities from unmanaged devices and triggers automatic remediation
AnswerA

This session policy works through the Microsoft Defender for Cloud Apps reverse proxy, which intercepts and inspects user requests in real time. By combining a 'device as unmanaged' condition with a sensitivity-label file filter, it can block the actual download action at the moment it occurs while still letting the user access the file in the browser. This is the only option that fulfills the requirement of allowing access but preventing a download from an unmanaged device.

Why this answer

A session policy in Microsoft Defender for Cloud Apps allows real-time control over user activities within a sanctioned cloud app. By configuring the action 'Block' on the download action for files with a specific sensitivity label, the administrator can block the download when the session is initiated from an unmanaged device, and the block action is logged in real time. This meets the requirement of blocking the download and logging the action simultaneously.

Exam trap

The trap here is that candidates confuse session policies with access policies or file policies, mistakenly thinking that blocking access to the entire app (Option C) or monitoring after the fact (Option B) achieves the same real-time blocking of a specific download action, when only a session policy provides the required granular, in-session control.

How to eliminate wrong answers

Option B is wrong because a file policy is designed for monitoring and alerting on files that match certain criteria (e.g., sensitivity labels) but does not provide real-time blocking of user actions like downloads; it generates alerts after the fact. Option C is wrong because an access policy blocks entire access to the cloud app from unmanaged devices, which is too broad—it would prevent any access, not just the download of sensitive files, and does not log the specific block action on the download. Option D is wrong because an activity policy monitors activities and can trigger automatic remediation (e.g., suspending a user), but it does not support real-time blocking of a specific download action within a session; it typically acts after the activity has occurred.

45
MCQhard

You are a security administrator for a company that uses Microsoft Defender XDR. You need to ensure that when a file is detected as malware by Microsoft Defender for Endpoint, the file is automatically blocked and added to the indicator list across all devices in the organization. What should you configure?

A.Enable the 'Block at first sight' feature in Microsoft Defender for Endpoint.
B.Configure an automated investigation and response (AIR) playbook to block the file when malware is detected.
C.Set up a Microsoft Defender for Cloud Apps file policy to block the file.
D.Create a custom indicator in Microsoft Defender for Endpoint with the action 'Block and remediate' and scope it to all devices.
AnswerD

Custom indicators in Defender for Endpoint allow you to define file hashes or certificates to block or allow. By setting the action to 'Block and remediate' and scoping to all devices, you ensure the file is blocked organization-wide. This directly meets the requirement.

Why this answer

Custom indicators in Microsoft Defender for Endpoint are the correct way to block files organization-wide. By creating an indicator with the action 'Block and remediate' and setting the scope to all devices, the file is blocked and remediated on any device. Other options either do not add to the indicator list or are not scoped organization-wide.

Exam trap

The trap here is confusing automated response actions or cloud protection features with the explicit indicator list, which is the only way to persistently block a file across all devices.

46
MCQmedium

A security administrator wants to simulate a realistic phishing attack to train users and measure their susceptibility. The simulation should be run from within Microsoft Defender XDR and provide detailed reporting. Which feature should the administrator use?

A.Advanced Hunting
B.Attack Simulation Training
C.Automated Investigation and Response
D.Threat Analytics
AnswerB

Attack Simulation Training is the dedicated feature in Microsoft Defender for Office 365 designed to create realistic phishing simulations and assign targeted training to users who interact with them. It provides prebuilt simulation templates, tracks metrics like click rate and credential submission, and automates follow-up training to improve user resilience. This matches the requirement to simulate a phishing attack and measure user response, so it is the correct answer.

Why this answer

Attack Simulation Training in Microsoft Defender XDR allows security administrators to create and launch realistic phishing campaigns directly from the Microsoft 365 Defender portal. It provides detailed reporting on user interactions, such as who clicked the link or entered credentials, enabling measurement of user susceptibility and targeted training follow-ups.

Exam trap

The trap here is that candidates often confuse Attack Simulation Training with Advanced Hunting, thinking that hunting queries can simulate attacks, but Advanced Hunting is purely a read-only data exploration tool with no simulation or user training features.

How to eliminate wrong answers

Option A is wrong because Advanced Hunting is a query-based tool for proactively searching for threats across raw data, not for simulating attacks or training users. Option C is wrong because Automated Investigation and Response (AIR) automatically responds to detected incidents by running playbooks and remediating threats, but it does not create or manage phishing simulations. Option D is wrong because Threat Analytics provides intelligence reports on active threats and adversary techniques, but it does not include simulation or user training capabilities.

47
Multi-Selecteasy

Which TWO features in Microsoft Defender for Office 365 help protect against zero-day malware in email attachments?

Select 2 answers
A.Safe Attachments
B.Mail flow rules
C.Anti-spam policies
D.Anti-phishing policies
E.Zero-hour auto purge (ZAP)
AnswersA, E

Safe Attachments routes email attachments to a hypervisor-isolated detonation chamber where files are opened and executed in a virtual environment to observe behavioral indicators. The resulting signals, combined with global threat intelligence, identify zero-day malware and trigger actions such as blocking, replacing, or alerting before delivery to the user.

Why this answer

Safe Attachments (Option A) is correct because it uses a detonation chamber environment to open email attachments in a virtualized sandbox, analyzing behavior for zero-day malware before delivery. This process catches unknown threats by executing the attachment and observing malicious actions, unlike signature-based detection.

Exam trap

The trap here is that candidates confuse Zero-hour auto purge (ZAP) as a proactive protection feature, when it is actually a reactive remediation tool that acts on already-delivered messages, not a prevention mechanism for zero-day malware in attachments.

48
MCQhard

A security administrator needs to create an automated investigation and response (AIR) playbook that automatically isolates a device whenever a high-severity alert from Microsoft Defender for Endpoint is generated. The playbook should run without requiring manual approval. Which capability in Microsoft 365 Defender should the administrator configure?

A.Automated investigation and response (AIR) action policy
B.Custom detection rule
C.Threat analytics
D.Attack simulation training
AnswerA

AIR action policies allow administrators to define automatic responses to specific alert types. By setting the isolation action for high-severity alerts from Microsoft Defender for Endpoint, the device can be isolated automatically without manual intervention.

Why this answer

Automated Investigation and Response (AIR) action policies in Microsoft 365 Defender allow administrators to define automated remediation actions—such as device isolation—that execute automatically when specific alert conditions are met, without requiring manual approval. The policy can be configured to trigger on high-severity alerts from Microsoft Defender for Endpoint, enabling fully automated containment of compromised devices.

Exam trap

The trap here is that candidates often confuse custom detection rules (Option B) with automated response capabilities, mistakenly thinking that creating a detection rule can also trigger automatic remediation, when in fact custom detection rules only generate alerts and require an AIR policy or manual action to respond.

How to eliminate wrong answers

Option B is wrong because custom detection rules are used to create custom analytics queries (e.g., using KQL) to detect specific threats or behaviors, but they do not directly configure automated response actions like device isolation; they rely on AIR policies or manual steps for remediation. Option C is wrong because Threat Analytics provides threat intelligence reports, vulnerability assessments, and mitigation recommendations, but it does not include the ability to configure automated response actions or playbooks. Option D is wrong because Attack Simulation Training is a tool for running simulated phishing and attack campaigns to test user awareness, not for automating incident response actions like device isolation.

49
MCQeasy

Your organization uses Microsoft Defender for Cloud Apps. You need to generate alerts when a user downloads a large number of files from Microsoft SharePoint Online in a short period. What should you create?

A.App Discovery policy
B.Activity policy
C.Anomaly Detection policy
D.Cloud Discovery policy
AnswerB

An Activity policy is the correct choice because it gives you full control to create a conditional rule that matches a specific activity, such as downloading a file, and then combines it with parameters like the user, device, IP address, or even a repeated-activity threshold. You can set the policy to trigger when a user performs more than a defined number of downloads within a short period, which directly detects mass download behavior. This is the standard mechanism in Defender for Cloud Apps for defining custom, business-specific activity monitoring.

Why this answer

Activity policies in Defender for Cloud Apps allow you to create custom rules to detect specific activities like mass download. Option A (App Discovery policy) is used to discover apps in use in your organization. Option C (Anomaly Detection policy) is for pre-built anomalies.

Option D (Cloud Discovery policy) is for shadow IT.

50
MCQeasy

You are a Microsoft 365 administrator for a company that uses Microsoft Defender XDR. A security analyst needs to view a unified list of incidents and alerts from Microsoft Defender for Endpoint, Microsoft Defender for Office 365, and Microsoft Defender for Identity. Where should the analyst go to see this unified view?

A.Microsoft 365 Defender portal (security.microsoft.com) under Incidents.
B.Azure Sentinel (azure.microsoft.com/services/azure-sentinel) under Incidents.
C.Microsoft Defender for Endpoint portal (securitycenter.windows.com) under Alerts.
D.Microsoft 365 compliance center (compliance.microsoft.com) under Alerts.
AnswerA

The Microsoft 365 Defender portal at security.microsoft.com provides a unified incidents queue that aggregates alerts from Microsoft Defender for Endpoint, Office 365, Identity, and Cloud Apps. This is the central location for cross-domain incident management, meeting the analyst's need for a unified view.

Why this answer

The Microsoft 365 Defender portal at security.microsoft.com is the centralized console for Microsoft Defender XDR. It aggregates alerts and incidents from Defender for Endpoint, Office 365, Identity, and Cloud Apps into a single queue, enabling analysts to investigate and respond across domains without switching portals.

Exam trap

The trap here is thinking that the individual Defender portals or Azure Sentinel provide the native unified incident view; only the Microsoft 365 Defender portal aggregates incidents across all Defender XDR workloads out of the box.

51
Matchingmedium

Match each Microsoft 365 threat scenario to the appropriate protection.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Anti-phishing policy in Defender for Office 365

Safe Attachments policy

Safe Links policy

Identity Protection and Conditional Access

Data Loss Prevention policy

Why these pairings

Correct matches: Phishing links → Safe Links; Malware attachments → Safe Attachments; Data leaks → DLP; Ransomware → Anti-ransomware policies. Common mistakes include confusing Safe Links with Safe Attachments and DLP with Defender protections.

52
MCQeasy

Your organization uses Microsoft Defender for Cloud Apps. You want to detect when a user accesses a sanctioned cloud app from an anonymous IP address. What should you configure?

A.Configure an app discovery policy
B.Set up a session policy to block access from anonymous IPs
C.Enable the cloud discovery shadow IT report
D.Create an activity policy in Defender for Cloud Apps
AnswerD

Activity policies in Microsoft Defender for Cloud Apps evaluate user activity against filters such as anonymous IP proxy, generating alerts when a sanctioned app is accessed from an anonymising source. This matches the detection requirement precisely.

Why this answer

An activity policy in Microsoft Defender for Cloud Apps is designed to monitor user activities and generate alerts based on conditions such as anonymous IP address usage. Since the requirement is to detect (not block) access from anonymous IPs, an activity policy with the 'Anonymous IP address' filter is the correct configuration. It leverages the built-in anonymous IP detection in Defender for Cloud Apps.

Exam trap

MS-102 often tests the difference between activity policies (detection/alerting on user actions) and session policies (real-time control of app sessions) — candidates pick session policy because 'anonymous IP' sounds like a blocking condition, but the question asks for detection.

How to eliminate wrong answers

Option A is wrong because an app discovery policy is used to identify shadow IT and unsanctioned apps from traffic logs, not to detect user activity from anonymous IPs. Option B is wrong because a session policy controls real-time session behavior (block/download restrictions) for sanctioned apps, and the requirement is detection, not blocking. Option C is wrong because the cloud discovery shadow IT report identifies unsanctioned apps, not anonymous IP access to sanctioned apps.

53
MCQeasy

As a Microsoft 365 administrator, you need to ensure that sensitive data is not shared externally via email. You configure Data Loss Prevention (DLP) policies in Microsoft Purview. What is the primary purpose of a DLP policy?

A.Prevent users from sending any external email.
B.Block all inbound emails from untrusted domains.
C.Encrypt all outgoing emails automatically.
D.Detect and prevent the sharing of sensitive information via email and other channels.
AnswerD

This is precisely the purpose of Microsoft Purview DLP: it uses sensitive information types, trainable classifiers, and exact data match to detect and prevent the unauthorized sharing of sensitive data across email, SharePoint, OneDrive, Teams, and endpoints. When a policy match occurs, DLP can block transmission, notify users with tips, or restrict access, thereby protecting regulated data such as financial and health information. DLP's scope extends beyond email to multiple channels, making this the accurate description of its core functionality.

Why this answer

Data Loss Prevention (DLP) policies in Microsoft Purview are designed to detect and prevent the sharing of sensitive information via email, Microsoft Teams, SharePoint, and other channels. Option A is incorrect because DLP does not block all external emails; it only blocks specific sensitive data. Option B is incorrect because blocking inbound emails from untrusted domains is typically handled by anti-spam or anti-phishing policies in Exchange Online Protection.

Option C is incorrect because email encryption is provided by Azure Information Protection or Office 365 Message Encryption, not DLP.

54
Multi-Selecthard

A company experiences a ransomware attack that encrypts files on several endpoints. The security team wants to use automated investigation and response (AIR) capabilities in Microsoft Defender XDR to contain the threat. Which TWO actions can be taken automatically by AIR? (Select TWO.)

Select 2 answers
A.Block the sender's email domain in Defender for Office 365.
B.Remove malicious files detected by Defender for Endpoint.
C.Isolate an affected device from the network.
D.Disable user accounts associated with the attack.
E.Reset user passwords for affected accounts.
AnswersB, C

AIR can automatically remediate endpoint artefacts by removing or quarantining malicious files that Defender for Endpoint detects, directly containing ransomware payloads without analyst intervention. This satisfies the scenario's requirement to contain the threat across affected endpoints.

Why this answer

Option B is correct because Microsoft Defender XDR's automated investigation and response (AIR) can automatically remediate endpoint threats by quarantining or removing malicious files that Defender for Endpoint detects during an investigation. Option C is correct because AIR can automatically isolate an affected device from the network to prevent lateral movement and further compromise while the investigation proceeds. Option A is not an AIR action in this context; blocking a sender's email domain is a manual or policy-driven action in Defender for Office 365, not an automatic endpoint containment response.

Option D is incorrect because disabling user accounts is an identity protection action typically performed manually or via Microsoft Entra ID Protection, not an automatic AIR containment step. Option E is also incorrect because password resets are identity remediation actions handled through Microsoft Entra ID, not automated endpoint containment by AIR.

Exam trap

MS-102 often tests which AIR actions are truly automatic versus which require approval — candidates overestimate AIR's scope and pick identity or email actions that are actually manual or playbook-driven.

55
MCQhard

A security analyst wants to create a custom detection rule that triggers when a device communicates with a new, unclassified IP address that has been flagged by Microsoft threat intelligence as potentially malicious. The rule should run every hour and create an incident if more than 5 such communications from the same device occur within a 24-hour window. Which advanced hunting tables should be joined in the KQL query for this rule?

A.DeviceNetworkEvents and IPReputation
B.DeviceProcessEvents and AlertInfo
C.DeviceFileEvents and DeviceIPInfo
D.EmailEvents and DeviceNetworkEvents
AnswerA

DeviceNetworkEvents records network connections including remote IPs. IPReputation provides Microsoft's threat intelligence score for IP addresses, allowing the rule to filter for connections to flagged IPs. These tables can be joined on the RemoteIP column.

Why this answer

The rule requires detecting network communications to potentially malicious IP addresses, which involves joining `DeviceNetworkEvents` (which logs network connections from devices) with `IPReputation` (which contains Microsoft's threat intelligence classifications for IP addresses). This join allows the query to filter for communications where the destination IP is flagged as malicious and then aggregate by device to trigger an incident when the count exceeds 5 within a 24-hour window.

Exam trap

The trap here is that candidates often confuse `DeviceNetworkEvents` with `DeviceProcessEvents` or `DeviceFileEvents`, mistakenly thinking process or file events can indicate network communication patterns, or they overlook that `IPReputation` is the specific table providing threat intelligence classification for IP addresses.

How to eliminate wrong answers

Option B is wrong because `DeviceProcessEvents` logs process creation events, not network communications, and `AlertInfo` contains metadata about alerts, not IP reputation data; this combination cannot detect communications with malicious IPs. Option C is wrong because `DeviceFileEvents` logs file creation/modification events, not network connections, and `DeviceIPInfo` provides IP configuration details (like DHCP leases) rather than threat intelligence reputation scores. Option D is wrong because `EmailEvents` tracks email delivery and phishing events, not device-level network communications, and joining it with `DeviceNetworkEvents` would not provide the required IP reputation data from Microsoft threat intelligence.

56
MCQmedium

A security analyst wants to create a custom detection rule in Microsoft Defender XDR that triggers when a device establishes a network connection to an IP address that has been recently observed in threat intelligence feeds as a new, malicious command-and-control server. The rule should analyze network communication events. Which advanced hunting table should be the primary data source for the Kusto Query Language (KQL) query?

A.DeviceProcessEvents
B.DeviceNetworkEvents
C.EmailEvents
D.AlertEvidence
AnswerB

DeviceNetworkEvents is the correct table because it records actual network connection events, including TCP, UDP, and ICMP traffic, with fields such as RemoteIP, RemotePort, LocalIP, LocalPort, and Protocol. A custom detection rule can filter directly on RemoteIP to flag connections to a known malicious IP address. It also provides DeviceId and other machine identifiers, enabling correlation with process and user context. This table is specifically designed for hunting network-based threats, making it the appropriate choice for IP-based detection rules.

Why this answer

DeviceNetworkEvents is the correct primary data source because it captures network connection events, including source and destination IP addresses, ports, and protocols. To detect a device connecting to a newly observed malicious command-and-control server, the KQL query must analyze network communication events, which are stored exclusively in this table.

Exam trap

Microsoft often tests the confusion between process-level and network-level tables, leading candidates to choose DeviceProcessEvents because they mistakenly think process creation is the primary indicator of malicious network activity.

How to eliminate wrong answers

Option A is wrong because DeviceProcessEvents logs process creation and execution events, not network connections; it cannot provide IP address or port information. Option C is wrong because EmailEvents tracks email delivery and phishing events, not device-level network connections to external IPs. Option D is wrong because AlertEvidence contains evidence linked to existing alerts, not raw network communication logs; it is used for investigating alerts, not as a primary source for custom detection rules.

57
MCQmedium

You are reviewing a conditional access policy in Microsoft Entra ID as shown in the exhibit. The policy is intended to block sign-ins that are considered risky. However, some high-risk users are still able to sign in. What is the most likely reason?

A.The policy requires user risk and sign-in risk to both be high
B.The policy requires multi-factor authentication instead of blocking
C.The policy does not include sign-in risk levels
D.The policy requires both user risk and sign-in risk to be at specified levels simultaneously
AnswerD

The policy applies only when both the user risk and sign-in risk conditions are satisfied at the same time, because the conditions are joined with AND logic. For example, even if user risk is High, a sign-in risk of Low prevents the policy from triggering. This simultaneous requirement is the key to understanding when the block control will be enforced.

Why this answer

The conditional access policy only blocks sign-ins when both user risk is high AND sign-in risk is medium or high. If a user has high user risk but low sign-in risk, the policy does not apply, allowing them to sign in. Options A, B, and C are incorrect: A states both must be high, but the policy may require medium or high for sign-in risk; B is not about MFA; C is wrong because sign-in risk levels are included.

58
MCQhard

A security administrator wants to prevent users from uploading files to unsanctioned cloud storage apps (e.g., personal Dropbox or Google Drive) from managed Windows devices. The solution must use a reverse proxy to control file uploads in real time. Which Microsoft Defender for Cloud Apps feature should the administrator configure?

A.App discovery policy
B.Access policy
C.Session policy
D.Activity policy
AnswerC

Session policies are the correct mechanism to prevent uploads because they utilize the Conditional Access App Control reverse proxy to intercept every HTTP request and response within an active cloud app session. The reverse proxy inspects the request payload and can identify a file upload attempt to unsanctioned storage, then block the action in real time or prompt the user with a warning. This capability is session-scoped, meaning it can allow other activities like reading or downloading while specifically blocking uploads. Thus a session policy provides the precise, real-time enforcement the requirement demands.

Why this answer

Session policy in Microsoft Defender for Cloud Apps uses reverse proxy capabilities to monitor and control user activities in real time. When configured with the 'Control file upload' action, it can block or restrict uploads to unsanctioned cloud storage apps like personal Dropbox or Google Drive from managed Windows devices, meeting the requirement exactly.

Exam trap

The trap here is confusing session policies (real-time reverse proxy control) with access policies (pre-session conditional access), leading candidates to choose access policy because it also uses Conditional Access, but it cannot inspect or block file uploads within an active session.

How to eliminate wrong answers

Option A is wrong because App discovery policy identifies cloud apps in use but does not enforce real-time controls via reverse proxy. Option B is wrong because Access policy controls access based on user/device context but does not inspect or block file uploads within a session. Option D is wrong because Activity policy detects and alerts on specific activities (e.g., uploads) but cannot block them in real time using a reverse proxy; it is reactive, not proactive.

59
MCQeasy

A company wants to use Microsoft Defender XDR to automatically investigate and remediate threats across email, endpoints, and identities. Which role is required to configure automation settings in the Microsoft 365 Defender portal?

A.Global Reader
B.Compliance Administrator
C.Security Administrator
D.Security Reader
AnswerC

The Security Administrator role in Microsoft Entra ID grants the permissions needed to configure automated investigation and remediation settings in the Microsoft 365 Defender portal, satisfying the requirement to manage Defender XDR automation across email, endpoints and identities.

Why this answer

The Security Administrator role in Microsoft Entra ID (Azure AD) grants the permissions needed to configure automation settings, including automated investigation and remediation (AIR) policies, in the Microsoft 365 Defender portal. This role is purpose-built for managing security features across Defender workloads without granting full tenant administrative rights.

Exam trap

MS-102 often tests the difference between read-only security roles (Security Reader, Global Reader) and the write-capable Security Administrator — candidates pick Security Reader thinking it can configure settings because it sounds security-focused.

How to eliminate wrong answers

Option A is wrong because Global Reader is a read-only role — it can view configuration and reports but cannot modify automation settings or any security policy. Option B is wrong because Compliance Administrator manages compliance-related features such as eDiscovery, data loss prevention, and retention policies, not Defender XDR automation settings. Option D is wrong because Security Reader, like Global Reader, is read-only for security features — it can view incidents and alerts but cannot configure or change automation policies.

60
MCQhard

Your organization uses Microsoft Defender for Identity (MDI) and Microsoft Defender for Cloud Apps. You receive an alert about a user who is performing an unusual number of failed logon attempts from a non-corporate IP address. The user is a member of the Finance group. What is the recommended first step?

A.Reset the user's password and require MFA.
B.Contact the user to verify if the activity is legitimate.
C.Disable the user account immediately.
D.Block the IP address in the firewall.
E.Close the alert as a false positive.
AnswerB

Verifying with the user confirms whether the failed logons are genuine mistyping or credential-stuffing before escalating. This satisfies the recommended first step, since contacting the account owner quickly establishes legitimacy without prematurely disabling a Finance user's access.

Why this answer

When an alert indicates unusual failed logon attempts from a non-corporate IP address, the recommended first step is to contact the user to verify if the activity is legitimate. This follows the principle of verification before action, as the activity could be due to a forgotten password or a misconfigured application. Option B is correct.

Option A (resetting password and requiring MFA) is premature without verification, as it may disrupt legitimate access. Option C (disabling the account) could be too disruptive and should only be done after confirming malicious intent. Option D (blocking the IP) might block legitimate users or shared IPs.

Option E (closing as false positive) skips investigation and could miss a real threat.

61
MCQhard

A ransomware alert is confirmed in Microsoft Defender XDR on a user device that is still communicating with other endpoints. What should the administrator do first to reduce spread while preserving the ability to investigate?

A.Isolate the affected device from the network
B.Collect a forensic package before taking containment action
C.Run a full antivirus scan before isolating the device
D.Wait for automated investigation to complete before responding
AnswerA

Isolate the affected device using Microsoft Defender for Endpoint's device isolation capability. Containment blocks all network traffic to and from the endpoint, including SMB and RDP, while preserving the management channel so Defender can continue telemetry and remediation. This immediately halts ransomware propagation, lateral movement, and command-and-control communication, giving responders time to analyze and remediate safely.

Why this answer

Immediately isolating the affected device from the network stops the ransomware from spreading laterally to other endpoints via SMB, RDP, or other protocols, while preserving the device's state for forensic analysis. Microsoft Defender XDR's device isolation feature blocks all inbound and outbound communication except with the Defender for Endpoint cloud service, allowing investigation to continue without the risk of further infection.

Exam trap

The trap here is that candidates often think they must preserve evidence first (Option B) or let automation run (Option D), but Microsoft explicitly prioritizes containment over collection in active ransomware outbreaks to prevent lateral spread.

How to eliminate wrong answers

Option B is wrong because collecting a forensic package before containment delays the response, allowing ransomware to continue spreading to other endpoints during the collection process. Option C is wrong because running a full antivirus scan before isolation is time-consuming and ineffective against active ransomware that may have already disabled or evaded the scanner, and it does not prevent lateral movement. Option D is wrong because waiting for automated investigation to complete gives the ransomware more time to encrypt files and propagate, whereas manual isolation is the recommended first step in confirmed ransomware incidents to contain the threat immediately.

62
MCQmedium

Your organization uses Microsoft 365 Defender. You need to configure automated investigation and response (AIR) to automatically remediate high-confidence phishing emails. What should you configure?

A.Automated investigation and response for collaboration content
B.Automated investigation and response for identities
C.Automated investigation and response for email
D.Automated investigation and response for devices
AnswerC

Automated investigation and response for email is the correct capability because it directly addresses threats found in email messages, including phishing, malware, and spam. When a suspicious email is detected, this AIR capability automatically launches an investigation, gathers evidence, and can take built-in remediation actions such as soft-deleting the message from all mailboxes, quarantining it, or blocking the sender. This is the only AIR workflow specifically tuned for email-borne threats in Microsoft 365 Defender.

Why this answer

Automated investigation and response (AIR) for email in Microsoft 365 Defender automatically investigates and remediates phishing emails, including high-confidence detections. Configuring AIR for email enables the system to take remediation actions like soft-deleting messages, blocking senders, and removing malicious content without manual intervention.

Exam trap

The trap is that AIR is a cross-workload capability, so candidates must map the specific scenario (phishing emails) to the email workload — picking devices or identities because those are more commonly discussed in Defender contexts.

How to eliminate wrong answers

Option A is wrong because AIR for collaboration content covers Teams, SharePoint, and OneDrive — not email phishing. Option B is wrong because AIR for identities covers compromised user accounts and identity-based attacks, not email content remediation. Option D is wrong because AIR for devices covers endpoint investigations and remediation, not email phishing emails.

63
MCQmedium

You are a security administrator for a company that uses Microsoft Defender XDR. You need to create a custom detection rule that triggers when a process named 'mimikatz.exe' is executed on any device. The rule should run every hour and generate an alert. Which of the following should you use to create this rule?

A.Microsoft Defender for Office 365 threat explorer
B.Microsoft 365 Defender incident queue
C.Microsoft Defender for Cloud Apps activity log
D.Microsoft Defender for Endpoint advanced hunting with a custom detection rule
AnswerD

Advanced hunting in Microsoft Defender for Endpoint allows you to write KQL queries against raw event data, and custom detection rules can be created from these queries to run on a schedule, such as hourly, and generate alerts when conditions are met. This is the correct method to detect process execution like mimikatz.exe.

Why this answer

Custom detection rules in Microsoft Defender for Endpoint allow security teams to create scheduled KQL queries that run against advanced hunting data and generate alerts when specific conditions are met. This is the appropriate tool for detecting process execution like mimikatz.exe on endpoints, as it provides the necessary data and scheduling capabilities.

Exam trap

The trap here is confusing the incident queue with a rule creation interface, when actually incident queue is only for viewing and managing existing alerts.

64
MCQmedium

Your organization uses Microsoft Defender for Office 365 and wants to simulate a phishing attack to train users. You need to configure a simulation that uses a URL link to a credential harvesting page. Which feature should you use?

A.Attack simulation training
B.Anti-phish policies
C.Safe Links policies
D.Safe Attachments policies
AnswerA

Attack simulation training in Microsoft Defender for Office 365 is the dedicated capability for creating and launching realistic phishing simulations. It provides pre-built payload templates and enables you to target specific users or groups, then track who clicked, submitted credentials, or reported the simulated message. This is the only option that actively generates simulated threats rather than enforcing protection on live traffic.

Why this answer

Attack simulation training in Microsoft Defender for Office 365 is the dedicated feature for creating and launching realistic phishing simulations, including those that use a URL link to a credential harvesting page. It allows administrators to configure payloads, target users, and track training completion, directly meeting the requirement to simulate a phishing attack for user education.

Exam trap

The trap here is that candidates confuse the protection features (Anti-phish, Safe Links, Safe Attachments) with the simulation feature, assuming that a security tool designed to block attacks can also be used to simulate them, but Microsoft separates simulation capabilities into the dedicated Attack simulation training feature.

How to eliminate wrong answers

Option B is wrong because Anti-phish policies are protection mechanisms that detect and block phishing attempts in real time, not tools for simulating attacks. Option C is wrong because Safe Links policies protect users by scanning and blocking malicious URLs in emails and Office documents, but they do not create or simulate phishing campaigns. Option D is wrong because Safe Attachments policies scan email attachments for malware and block dangerous files, but they have no capability to simulate phishing attacks or credential harvesting pages.

65
Multi-Selecthard

A security administrator is configuring Microsoft Defender for Cloud Apps. The administrator needs to discover which cloud apps are being used in the organization and then block usage of unsanctioned apps in real time using a reverse proxy. Which two Defender for Cloud Apps features must be configured? (Select the two correct options.)

Select 2 answers
A.Cloud Discovery
B.App governance
C.Conditional Access App Control
D.OAuth app permissions
AnswersA, C

Cloud Discovery is the feature in Microsoft Defender for Cloud Apps that ingests and analyzes traffic logs from network proxies and firewalls to identify all cloud apps in use, including unsanctioned shadow IT. It assigns risk scores to each discovered app and allows you to sanction or unsanction them based on organizational policy. This analysis is the foundational step for any subsequent control, such as Conditional Access App Control.

Why this answer

Cloud Discovery is the correct feature because it identifies which cloud apps are in use by analyzing traffic logs from the organization's network. This provides the visibility needed to determine which apps are unsanctioned. Conditional Access App Control is the correct feature because it uses a reverse proxy to enforce real-time access controls, blocking unsanctioned apps at the session level.

Exam trap

The trap here is that candidates confuse App governance (which manages OAuth app permissions) with the reverse proxy functionality of Conditional Access App Control, or assume Cloud Discovery alone is sufficient for blocking, when it only provides visibility.

66
MCQeasy

A security administrator needs to view a unified incident queue that correlates alerts from Microsoft Defender for Endpoint, Microsoft Defender for Office 365, and Microsoft Defender for Identity. Which console should the administrator open?

A.Microsoft 365 Defender portal (security.microsoft.com)
B.Azure Security Center
C.Microsoft Endpoint Manager admin center
D.Microsoft Purview compliance portal
AnswerA

Microsoft 365 Defender portal (security.microsoft.com) is the single security operations console that aggregates alerts and incidents from Defender for Endpoint, Defender for Office 365, Defender for Identity, and Defender for Cloud Apps. Its unified incident queue correlates related alerts into a single incident, enabling triage, investigation, and response across all Microsoft 365 Defender workloads. This portal is the correct destination for viewing a unified incident queue.

Why this answer

The Microsoft 365 Defender portal (security.microsoft.com) provides a unified incident queue that aggregates and correlates alerts from Microsoft Defender for Endpoint, Defender for Office 365, Defender for Identity, and Defender for Cloud Apps. This single-pane-of-glass view enables security administrators to investigate and respond to cross-domain threats without switching between separate consoles.

Exam trap

The trap here is that candidates often confuse the Microsoft 365 Defender portal with Azure Security Center (now Defender for Cloud), mistakenly thinking that all security alerts converge in Azure, when in fact the unified incident queue for Microsoft 365 Defender workloads is exclusive to security.microsoft.com.

How to eliminate wrong answers

Option B is wrong because Azure Security Center (now Microsoft Defender for Cloud) focuses on securing cloud workloads (VMs, containers, SQL) and does not provide a unified incident queue for Microsoft 365 Defender workloads. Option C is wrong because Microsoft Endpoint Manager admin center (intune.microsoft.com) is used for device management, compliance policies, and app deployment, not for security incident correlation. Option D is wrong because the Microsoft Purview compliance portal (compliance.microsoft.com) is dedicated to data governance, eDiscovery, and compliance management, not for real-time threat alert correlation from Defender products.

67
MCQeasy

Your organization uses Microsoft Defender for Cloud Apps. You need to be alerted when a user accesses a cloud app from a risky IP address. What should you configure?

A.Create an anomaly detection policy with the 'Activity from risky IP address' template.
B.Create a session policy to monitor risky IP addresses.
C.Create a file policy to detect access from risky IPs.
D.Create an access policy to block risky IPs.
AnswerA

The 'Activity from risky IP address' template is a built-in anomaly detection policy in Microsoft Defender for Cloud Apps that leverages Microsoft threat intelligence to identify IP addresses associated with malicious activity, such as anonymous proxies, Tor exit nodes, or known botnets. When a user performs an activity from one of these IPs, the policy generates an alert, giving security teams immediate visibility into the potentially compromised session. This is exactly the alerting capability needed in this scenario.

Why this answer

An anomaly detection policy can alert on activities from risky IP addresses. Option B is wrong because session policies control real-time access. Option C is wrong because file policies monitor data.

Option D is wrong because access policies control access based on conditions.

68
MCQhard

Your organization uses Microsoft Defender for Endpoint and Microsoft Defender for Identity. A user reports that their account was used to send a large volume of email messages to internal recipients, which appears to be a potential account compromise. You need to determine if the account is compromised and if any lateral movement occurred. Which data sources should you analyze in Microsoft Defender XDR?

A.EmailEvents and EmailAttachmentInfo
B.DeviceNetworkEvents and DeviceProcessEvents
C.DeviceEvents and DeviceNetworkEvents
D.IdentityLogonEvents, EmailEvents, and DeviceProcessEvents
AnswerD

Together, these tables provide a complete attack chain: IdentityLogonEvents records sign-in and logon attempts, revealing suspicious authentication patterns tied to a specific account; EmailEvents tracks email send/receive activity, enabling correlation of a phishing email or malicious attachment; and DeviceProcessEvents logs process creation, which exposes lateral movement when a compromised account launches a remote service, script, or executable. Joining these tables on user SID and device ID lets an investigator reconstruct the timeline from email receipt to identity compromise to endpoint execution.

Why this answer

IdentityLogonEvents (from Microsoft Defender for Identity) provide logon activities, EmailEvents (from Microsoft Defender for Office 365) show email sending patterns, and DeviceProcessEvents (from Microsoft Defender for Endpoint) reveal process creations that may indicate lateral movement (e.g., PsExec, WMI). Together, these three data sources allow correlation of identity, email, and device events to confirm a compromise and detect lateral movement. Option A is incorrect because EmailEvents and EmailAttachmentInfo cover only email context, lacking identity and lateral movement data.

Option B is incorrect because DeviceNetworkEvents and DeviceProcessEvents lack identity and email context. Option C is incorrect because DeviceEvents and DeviceNetworkEvents also miss identity and email context.

69
MCQmedium

A company's security team needs to investigate a suspicious email that was reported by a user. The email was not blocked by Exchange Online Protection (EOP) and was delivered to the user's inbox. The security team wants to use Microsoft Defender XDR to analyze the email and its attachments. Which feature should they use to submit the email for automated investigation?

A.Submissions
B.Advanced Hunting
C.Threat Explorer
D.Attack Simulator
AnswerA

Submissions in Microsoft Defender XDR lets administrators send user-reported or suspicious emails, including attachments, for automated investigation and rescanning. It satisfies the requirement because the message was delivered, so it must be submitted manually rather than relying on EOP blocking.

Why this answer

Microsoft Defender XDR's Submissions feature (under Email & Collaboration > Submissions) allows security teams to submit suspicious emails, attachments, and URLs to Microsoft for automated analysis. When a user reports a phish that EOP missed, the admin can submit it via Submissions, which triggers automated investigation, detonation, and re-classification. This is the correct tool for analyzing a specific reported email and its attachments.

Exam trap

MS-102 often tests the distinction between investigation tools — the trap is confusing Threat Explorer (viewing threats) with Submissions (reporting threats for analysis), or picking Advanced Hunting when the question asks about submitting a specific email.

How to eliminate wrong answers

Option B (Advanced Hunting) is wrong because it is a KQL-based query tool for proactively searching telemetry across Defender workloads — it does not submit emails for automated investigation or re-classification. Option C (Threat Explorer) is wrong because it is a real-time reporting and investigation dashboard for email threats, but it does not submit items to Microsoft for analysis; it is for viewing and filtering existing threat data. Option D (Attack Simulator) is wrong because it is used to create and run simulated phishing campaigns for user training, not to analyze real reported emails.

70
MCQeasy

You are a security administrator for a company that uses Microsoft Defender XDR. You need to generate a report that shows the number of incidents closed as true positive, false positive, and benign in the last 30 days. You want to use built-in features without writing custom queries. What should you do?

A.Use the Microsoft Defender for Endpoint reports section.
B.Use the Device health report in Microsoft Defender XDR.
C.Navigate to Threat analytics in the Defender XDR portal.
D.In the Microsoft Defender XDR portal, go to Reports > General > Incident summary.
AnswerD

The Incident summary report is a built-in Defender XDR report that aggregates incident classifications, including true positive, false positive and benign counts, over a selectable period such as 30 days. It satisfies the no-custom-queries constraint directly, unlike advanced hunting or custom workbooks.

Why this answer

The Microsoft Defender XDR portal includes a built-in Reports section under General with an Incident summary report that shows incident counts by classification (true positive, false positive, benign) over a selected period such as 30 days. This requires no custom queries and directly provides the requested metrics. Navigating to Reports > General > Incident summary is the correct built-in path.

Exam trap

MS-102 often tests the trap of choosing Advanced Hunting or Threat Analytics for reporting when the question specifies 'built-in features without custom queries' — the correct answer is the built-in Reports section.

How to eliminate wrong answers

Option A is wrong because the Defender for Endpoint reports section focuses on endpoint-specific reports (device health, threat protection) and does not provide the cross-workload incident classification summary. Option B is wrong because the Device health report shows endpoint sensor health and onboarding status, not incident classifications. Option C is wrong because Threat analytics provides curated threat intelligence and campaign tracking, not a count of incidents by classification.

71
MCQeasy

Your organization uses Microsoft Defender for Office 365. A user reports receiving a phishing email that bypassed the built-in anti-phishing policy. You need to analyze the email headers to determine why it was not detected. What should you use?

A.Attack Simulator in Microsoft Defender for Office 365
B.Threat Explorer in Microsoft Defender for Office 365
C.Message trace in Exchange admin center
D.Quarantine page in Microsoft Defender for Office 365
AnswerB

Threat Explorer provides message trace, detection technology and delivery location per email, letting you determine which anti-phishing control failed and why. It is the Microsoft Defender for Office 365 tool built for investigating individual messages.

Why this answer

Threat Explorer (part of Microsoft 365 Defender's Email & Collaboration section) provides detailed email metadata, including full message headers, delivery action, and the specific policy or filter that processed the message. It lets administrators trace why a message was allowed, blocked, or delivered to junk, and it surfaces the anti-phishing verdict, spoof intelligence, and detection technology that evaluated the message. This is the correct tool for post-incident header analysis of a phishing message that bypassed filtering.

Exam trap

MS-102 often tests the distinction between tools that show message routing (Message trace) versus tools that show detection verdicts and headers (Threat Explorer) — candidates confuse the two because both are email investigation tools.

How to eliminate wrong answers

Option A is wrong because Attack Simulator is used to launch simulated phishing campaigns for user training and to measure click rates — it does not analyze real inbound email headers. Option C is wrong because Message trace in the Exchange admin center only shows the routing and delivery status of messages (sent, delivered, failed) and does not expose anti-phishing verdicts, header-level detection details, or the reason a message bypassed a policy. Option D is wrong because the Quarantine page only lists and manages messages that were already quarantined — a message that bypassed the filter and landed in the inbox would not appear there.

72
Multi-Selecthard

Which THREE features are included in Microsoft Defender for Office 365 Plan 2 but NOT in Plan 1? (Choose three.)

Select 3 answers
A.Anti-phishing policies
B.Safe Links
C.Automated Investigation and Response (AIR)
D.Threat Explorer
E.Attack Simulation Training
AnswersC, D, E

Automated Investigation and Response (AIR) is a premium Plan 2 capability that uses orchestration and automation to investigate alerts, analyze threat signals, and take recommended or automated remediation actions. It goes beyond passive detection by proactively resolving incidents without requiring continuous manual oversight, making it a key differentiator for Plan 2 licensing.

Why this answer

Automated Investigation and Response (AIR) (C) is exclusive to Defender for Office 365 Plan 2, as it uses automated playbooks to investigate and remediate threats, which Plan 1 does not include. Threat Explorer (D) is also a Plan 2-only feature, providing real-time and historical threat hunting and reporting capabilities that are absent from Plan 1. Attack Simulation Training (E) is likewise included only in Plan 2, enabling organizations to run simulated phishing and social engineering attacks to train users.

Anti-phishing policies (A) and Safe Links (B) are available in both Plan 1 and Plan 2, so they are not correct answers for features unique to Plan 2.

Exam trap

MS-102 often tests the boundary between P1 protection features and P2 investigation features, so candidates incorrectly include Safe Links or anti-phishing as P2 exclusives.

73
MCQmedium

A security analyst runs the above KQL query in Microsoft 365 Defender. The query returns an empty result set. Which is the most likely reason?

A.The time range is too wide and the query times out.
B.No antivirus detection events for files with 'ransomware' or 'encrypt' in the filename occurred in the last 7 days.
C.The 'has_any' operator is used incorrectly; it should be 'contains' for each condition.
D.The DeviceEvents table does not contain antivirus detection events.
AnswerB

The query returned zero rows because no antivirus detection events with a filename containing the exact term 'ransomware' or 'encrypt' were logged in the last 7 days. This is a valid, actionable result; it does not mean the query is flawed. To uncover broader suspicious activity, reduce reliance on the filename term match or use contains for substring matching, and consider expanding the time range or adding related tables like DeviceFileEvents.

Why this answer

The KQL query filters DeviceEvents for antivirus detection events where the filename contains 'ransomware' or 'encrypt' within the last 7 days. An empty result set simply means no such events matched the filter criteria during that period — this is a normal, expected outcome when no ransomware-like files were detected, not an error condition. The query syntax and table are valid; the absence of data is the answer.

Exam trap

MS-102 often tests whether candidates confuse an empty query result with a query error or misconfiguration, when in fact the absence of matching events is the correct interpretation.

How to eliminate wrong answers

Option A is wrong because a wide time range does not cause a timeout in Microsoft 365 Defender's advanced hunting — queries are limited by result count and execution time, but a 7-day window is well within limits and would not silently return empty. Option C is wrong because 'has_any' is a valid KQL operator that checks if any of the specified values appear in the field; it is not a syntax error, and 'contains' would be less efficient and semantically different. Option D is wrong because the DeviceEvents table does contain antivirus detection events (e.g., AntivirusDetection action types), so the table is the correct source.

74
Multi-Selecthard

Your organization uses Microsoft Defender for Cloud Apps. You need to create a policy that detects when a user shares a file containing sensitive data with an external domain. Which three components must you configure in the policy? (Choose three.)

Select 3 answers
A.A content inspection method (e.g., DLP)
B.A governance action (e.g., alert, block)
C.A filter to specify the sharing type (e.g., external)
D.A session control action
E.An access token condition
AnswersA, B, C

Content inspection, such as DLP, examines the file payload to confirm it actually contains sensitive data, satisfying the stem's sensitive-data condition. Sharing filters alone cannot determine content; inspection is what distinguishes a genuine sensitive-data exposure from an ordinary external share.

Why this answer

The correct components for a file policy in Microsoft Defender for Cloud Apps are: a filter to specify the scope (e.g., sharing with external users), a content inspection method (e.g., DLP) to detect sensitive data, and a governance action (e.g., alert or block). Option D is incorrect because session control actions are used in session policies, not file policies. Option E is incorrect because access token conditions are not a component of file policies.

75
MCQmedium

A security administrator wants to prevent Microsoft Office applications (Word, Excel, PowerPoint) from creating child processes, which is a common technique used by malware to execute malicious code. Which attack surface reduction (ASR) rule should be enabled?

A.Block all Office applications from creating child processes
B.Block executable files from running unless they meet a prevalence, age, or trusted list criteria
C.Block Office applications from creating executable content
D.Block Win32 API calls from Office macros
AnswerA

This Attack Surface Reduction (ASR) rule, identified by rule GUID 26190899-1602-49e8-8b27-eb1d0a1ce869, specifically targets the parent-child relationship where winword.exe, excel.exe, or powerpnt.exe attempts to launch any secondary executable. By blocking the creation of child processes such as cmd.exe, powershell.exe, or wscript.exe, it directly neutralizes the described macro-based attack chain before the payload can execute. This is the only option among these that was designed to stop exactly this process-spawn behavior.

Why this answer

The ASR rule 'Block all Office applications from creating child processes' (GUID: D4F940AB-401B-4EFC-AADC-AD5F3C50688A) specifically prevents Word, Excel, and PowerPoint from spawning child processes such as cmd.exe, PowerShell, or wscript.exe. This directly mitigates a common malware technique where Office macros or exploits launch malicious executables. The rule is part of Microsoft Defender for Endpoint's attack surface reduction capabilities and is designed to stop process injection and lateral movement without blocking legitimate Office functionality.

Exam trap

The trap here is that candidates confuse 'creating child processes' with 'creating executable content' or 'blocking Win32 API calls,' leading them to choose options that address file writes or macro restrictions rather than the specific process spawning behavior.

How to eliminate wrong answers

Option B is wrong because 'Block executable files from running unless they meet a prevalence, age, or trusted list criteria' is an ASR rule that targets executable files (e.g., .exe, .dll) based on reputation, not Office child process creation. Option C is wrong because 'Block Office applications from creating executable content' prevents Office apps from writing executable files (e.g., .exe, .scr) to disk, but does not block the spawning of child processes. Option D is wrong because 'Block Win32 API calls from Office macros' disables macros from calling Win32 APIs (e.g., via VBA), which is a different attack vector; it does not prevent Office apps from creating child processes through other means like OLE or DDE.

Page 1 of 3 · 197 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Defender Xdr Security questions.