Courseiva

MS-102 · topic practice

Manage security and threats by using Microsoft Defender XDR practice questions

This domain covers Microsoft Defender XDR workload integration and response: Defender for Identity, Defender for Cloud Apps, Defender for Endpoint, and Microsoft Sentinel. Questions present operational scenarios requiring you to select the correct investigation surface, policy components, data tables, or integration setting rather than recite definitions.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Manage security and threats by using Microsoft Defender XDR

What the exam tests

What to know about Manage security and threats by using Microsoft Defender XDR

You must be able to investigate cross-workload incidents in the Defender XDR portal, configure Defender for Cloud Apps detection policies, and connect Defender XDR to Microsoft Sentinel. The critical point is knowing which portal, table, or connector surfaces each alert and where unified incidents actually appear.

Investigating Defender for Identity alerts such as DCSync in the Defender XDR incidents queue

Building Defender for Cloud Apps anomaly detection policies using activity, filter, and alert components

Integrating Defender XDR with Microsoft Sentinel for unified incident creation and bi-directional sync

Querying Defender for Endpoint advanced hunting tables like DeviceInfo and DeviceProcessEvents

Watch out for

Common Manage security and threats by using Microsoft Defender XDR exam traps

  • ▸Treating Defender for Identity alerts as standalone and missing the correlated incident in the unified Defender XDR portal.
  • ▸Confusing Defender for Cloud Apps policy components with Conditional Access controls instead of activity filters and detection settings.
  • ▸Assuming Sentinel integration is automatic, ignoring the connector configuration and incident creation rules required for unified incidents.

Practice set

Manage security and threats by using Microsoft Defender XDR questions

20 questions · select your answer, then reveal the explanation

A security operations team uses Microsoft Defender XDR. They want to create a custom detection rule that alerts when a specific process (e.g., wscript.exe) launches from a user's temp directory and then performs a network connection to an external IP. Which advanced hunting query language should they use?

A security operations team wants to receive real-time alerts when a user is at high risk of having their account compromised based on unusual sign-in patterns. Which Microsoft Defender XDR component should they configure?

A security analyst wants to create a custom detection rule in Microsoft Defender XDR that triggers when a user receives a phishing email and later clicks a link to a known malicious domain from their device. The rule will use advanced hunting queries. Which two tables should be joined to detect the click event from the device?

A security analyst wants to search for instances where a user received a phishing email that was delivered to their inbox, and then later clicked a link within that email that led to a known malicious domain. Which two advanced hunting tables should be joined to identify both the email delivery and the link click events? (Choose the option that correctly identifies the primary table pair.)

A security analyst is investigating a potential lateral movement attack. They need to identify which processes were created on a compromised device and then which network connections were made by those processes. Which two advanced hunting tables should the analyst join in a KQL query?

A security analyst wants to create a custom detection rule in Microsoft Defender XDR that triggers when a user receives a phishing email (delivered to inbox) and then, from their Windows device, establishes a network connection to a known malicious IP address. The rule will be based on an advanced hunting query. Which two tables should the analyst join in the KQL query to capture both the email delivery event and the network connection event?

Question 7hardmultiple choice
Read the full Ansible explanation →

A security administrator needs to configure an automated investigation and response (AIR) playbook in Microsoft 365 Defender that will automatically isolate a device whenever a high-severity alert from Microsoft Defender for Endpoint is generated. The playbook must run without requiring manual approval. Which configuration must the administrator set to achieve automatic device isolation?

A security analyst is building a custom detection rule in Microsoft 365 Defender to identify when a user clicks a malicious URL in a phishing email and subsequently visits the malicious site from their corporate device. The analyst plans to use advanced hunting with Kusto Query Language (KQL). Which two tables must be joined to capture both the URL click event and the network connection to the malicious site?

A security administrator needs to block executable files from running from the %TEMP% folder on Windows devices to prevent common malware execution. Which attack surface reduction (ASR) rule should be enabled?

A security analyst wants to create a custom detection rule in Microsoft 365 Defender that triggers when a PowerShell process with suspicious command-line arguments is detected on a device, and within 5 minutes, an outbound network connection to a known malicious IP occurs. Which two advanced hunting tables must be joined in the KQL query?

A security analyst is creating a custom detection rule in Microsoft 365 Defender Advanced Hunting. The rule should fire when a Windows device exhibits this sequence of events within 3 minutes: 1) A PowerShell process runs with an encoded command, 2) A service is created with a random name, and 3) An outbound network connection to a suspicious IP address is observed. Which three Advanced Hunting tables must be joined in the KQL query to create this detection?

A security analyst is creating a custom detection rule in Microsoft 365 Defender Advanced Hunting. The rule should trigger when a process named 'powershell.exe' is launched with command-line arguments containing '-EncodedCommand', and within 5 minutes a service is created on the same device. Which two Advanced Hunting tables must be joined in the KQL query to create this detection?

A security analyst is creating a custom detection rule in Microsoft 365 Defender Advanced Hunting. The rule should detect when a user opens a malicious email attachment, which launches a PowerShell process, and then that PowerShell process makes an outbound connection to a known malicious IP address. Which two Advanced Hunting tables must be joined in the KQL query?

A security analyst is creating a custom detection rule in Microsoft 365 Defender Advanced Hunting. The rule should trigger when a user opens a malicious Office document, which launches a process named cmd.exe from Microsoft Word, and then that cmd.exe process makes an outbound connection to a known malicious IP address. Which two Advanced Hunting tables must be joined in the KQL query?

A security analyst wants to create a custom detection rule in Microsoft 365 Defender Advanced Hunting that alerts when a user receives a phishing email and clicks a malicious link within 10 minutes. Which two tables must be joined in the KQL query?

A security analyst wants to create a custom detection rule in Microsoft 365 Defender Advanced Hunting that alerts when a process spawned by Microsoft Word (winword.exe) makes an outbound connection to a known malicious IP address. Which two Advanced Hunting tables must be joined in the KQL query?

A security analyst is creating a custom detection rule in Microsoft 365 Defender Advanced Hunting. The rule should detect when a user receives a malicious email attachment and then opens the attachment, resulting in a process being created (e.g., .exe file). Which two Advanced Hunting tables must be joined to correlate the email attachment with the resulting process?

A security analyst is investigating a potential attack where a user received a malicious email with an HTML attachment. The HTML file, when opened, fetched a JavaScript payload from a remote server that then dropped a binary on the user's machine and executed it. The analyst wants to create a custom detection rule in Microsoft 365 Defender Advanced Hunting that alerts when an email contains an HTML attachment with an external link, and that attachment is opened, causing a process creation. Which two tables should the analyst join in the KQL query to correlate the email attachment with the resulting process?

You are a Microsoft 365 administrator for a multinational organization. You are implementing Microsoft Defender XDR to provide centralized threat management across multiple domains. Which three of the following capabilities are core components of Microsoft Defender XDR? (Choose three.)

As a security administrator, you are tuning automated investigation and response (AIR) capabilities in Microsoft Defender XDR. You need to ensure that the system can automatically remediate threats while minimizing false positives. Which three of the following actions can be taken by automated investigation and response in Microsoft Defender XDR? (Choose three.)

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Manage security and threats by using Microsoft Defender XDR sessions

Start a Manage security and threats by using Microsoft Defender XDR only practice session

Every question in these sessions is drawn from the Manage security and threats by using Microsoft Defender XDR domain — nothing else.

Related practice questions

Related MS-102 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the MS-102 exam test about Manage security and threats by using Microsoft Defender XDR?
You must be able to investigate cross-workload incidents in the Defender XDR portal, configure Defender for Cloud Apps detection policies, and connect Defender XDR to Microsoft Sentinel. The critical point is knowing which portal, table, or connector surfaces each alert and where unified incidents actually appear.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Manage security and threats by using Microsoft Defender XDR questions in a focused session?
Yes — the session launcher on this page draws every question from the Manage security and threats by using Microsoft Defender XDR domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other MS-102 topics?
Use the topic links above to move to related areas, or go back to the MS-102 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the MS-102 exam covers. They are not copied from any real exam or dump site.