Courseiva

CCNA Defender Xdr Security Questions

47 of 197 questions · Page 3/3 · Defender Xdr Security topic · Answers revealed

151
MCQhard

You are configuring Microsoft Defender for Office 365 to protect against business email compromise (BEC) attacks. Which policy setting should you enable to analyze email sender behavior and detect impersonation attempts?

A.Safe Attachments policy - Dynamic Delivery
B.Anti-phishing policy - Impersonation protection
C.Safe Links policy - URL scan
D.Anti-malware policy - Malware filter
AnswerB

Impersonation protection within the anti-phishing policy uses mailbox intelligence and spoof detection to model sender behaviour and flag messages impersonating internal users or trusted domains. This satisfies the requirement to analyse sender behaviour and detect business email compromise impersonation attempts.

Why this answer

Anti-phishing policies in Microsoft Defender for Office 365 include impersonation protection settings that analyze sender behavior and detect attempts to impersonate users, domains, or trusted senders. Enabling impersonation protection specifically addresses BEC by using mailbox intelligence and spoof intelligence to identify anomalous sender patterns.

Exam trap

MS-102 often tests the difference between Safe Attachments, Safe Links, anti-malware, and anti-phishing, and candidates may incorrectly associate BEC detection with attachment scanning rather than impersonation protection.

How to eliminate wrong answers

Option A is wrong because Safe Attachments with Dynamic Delivery focuses on detonating attachments in a sandbox and delivering the email without the attachment until scanning completes; it does not analyze sender behavior. Option C is wrong because Safe Links URL scanning protects against malicious URLs, not sender impersonation. Option D is wrong because anti-malware policies filter known malware signatures and do not detect impersonation or BEC tactics.

152
MCQhard

Your organization is a financial services company with 5,000 users. You use Microsoft Defender XDR, including Defender for Endpoint Plan 2, Defender for Identity, Defender for Office 365 Plan 2, and Defender for Cloud Apps. You have recently deployed Microsoft Copilot for Security to assist your security operations center (SOC) analysts. A high-severity incident is generated: 'A user named jdoe accessed a malicious IP address from their device, and then logged into Azure Portal from an anonymous IP address. Defender for Identity detected a suspicious Kerberos ticket request from the same user's domain controller. The SOC analysts are overwhelmed with alerts and need to quickly understand the full scope of the incident, including related alerts, impacted assets, and recommended actions. They also want to use natural language to ask questions about the incident. What should you do to enable the analysts to efficiently investigate this incident?

A.Train the analysts to use Advanced Hunting to query across all data sources and build custom KQL queries to correlate the alerts.
B.Create custom detection rules in Microsoft Defender XDR to generate more specific alerts for similar activity.
C.Use Microsoft Copilot for Security integrated with Microsoft Defender XDR to get a natural language summary of the incident, ask follow-up questions, and receive recommended actions.
D.Configure automated investigation and remediation to automatically contain the threat and then review the results.
AnswerC

Copilot for Security embedded in Defender XDR correlates the incident's alerts, entities and Defender for Identity signals, then answers natural-language questions and surfaces recommended actions. This directly satisfies the analysts' need to rapidly scope the incident across products without manual triage.

Why this answer

Microsoft Copilot for Security integrated with Microsoft Defender XDR provides natural language summaries of incidents, allows follow-up questions, and offers recommended actions. This directly addresses the SOC analysts' need to quickly understand the full scope and use natural language, reducing investigation time.

Exam trap

MS-102 often tests the misconception that Advanced Hunting or automated investigation alone can provide natural language summaries, but only Copilot for Security offers that capability.

How to eliminate wrong answers

Option A is wrong because Advanced Hunting with KQL requires manual query writing and expertise, which is time-consuming and does not provide natural language interaction. Option B is wrong because custom detection rules generate more alerts, which would increase the noise rather than help investigate the existing incident. Option D is wrong because automated investigation and remediation can contain threats but does not provide natural language summaries or recommended actions for analysts to understand the incident scope.

153
MCQhard

Your organization has Microsoft 365 E5 licenses and uses Microsoft Defender for Office 365. You need to ensure that users are warned before clicking on malicious URLs in email messages, even if the URL is clicked after the email is delivered. Which policy should you configure?

A.Anti-malware policy
B.Safe Attachments policy
C.Safe Links policy
D.Anti-phishing policy
AnswerC

Safe Links rewrites URLs and checks them at click time, so users are warned or blocked even after delivery. This satisfies the requirement to protect clicks occurring post-delivery, unlike Safe Attachments, which detonates attachments, or anti-phishing policies, which act on delivery.

Why this answer

Safe Links policy is correct because it provides time-of-click protection, which scans URLs in email messages at the moment the user clicks them, even after delivery. This ensures users are warned or blocked from accessing malicious URLs that may have been benign at the time of delivery but later weaponized. Anti-malware, Safe Attachments, and Anti-phishing policies do not offer this post-delivery click-time verification.

Exam trap

The trap here is that candidates often confuse Safe Attachments (which handles files) with Safe Links (which handles URLs), or assume that Anti-phishing policies cover all link-based threats, but only Safe Links provides the specific time-of-click protection described in the question.

How to eliminate wrong answers

Option A is wrong because Anti-malware policy focuses on detecting and removing malware in email attachments and messages at the time of delivery, not on URL click-time protection. Option B is wrong because Safe Attachments policy specifically handles email attachments by detonating them in a sandbox environment, not URLs embedded in messages. Option D is wrong because Anti-phishing policy protects against impersonation and phishing attempts using spoofing intelligence and impersonation detection, but it does not provide click-time URL scanning or warning for malicious links.

154
MCQeasy

Your organization uses Microsoft Defender for Office 365. You need to ensure that malicious links in email messages are blocked at the time of click by checking the link reputation in real time. What should you enable?

A.Anti-spam policy.
B.Safe Attachments policy.
C.Safe Links policy.
D.Anti-phishing policy.
AnswerC

A Safe Links policy in Microsoft Defender for Office 365 rewrites URLs and verifies link reputation at click time, blocking malicious destinations in real time. This satisfies the time-of-click requirement, unlike Safe Attachments, which detonates attachments rather than evaluating links.

Why this answer

Safe Links policy in Defender for Office 365 provides real-time link reputation checking at the time of click. It rewrites URLs and checks them against a dynamic list of known malicious links when users click them. Option A is incorrect because anti-spam policies filter spam emails, not malicious links.

Option B is incorrect because Safe Attachments scans email attachments for malware, not links. Option D is incorrect because anti-phishing policies protect against phishing attempts but do not perform real-time link checking.

155
MCQmedium

Your organization uses Microsoft Defender for Endpoint. A user reports that their device is not receiving security updates. You need to ensure that the device is properly onboarded to Defender for Endpoint. Which log should you check first?

A.Event Viewer Application logs
B.System logs
C.Microsoft Defender for Endpoint client logs
D.Windows Update logs
AnswerC

The Microsoft Defender for Endpoint client logs are the authoritative source for troubleshooting onboarding and update issues. These logs, located in C:\ProgramData\Microsoft\Windows Defender Advanced Threat Protection\Logs, include files like MicrosoftDefenderATPOnboarding.log and MicrosoftDefenderATPUpdate.log that record sensor registration, machine ID assignment, and signature update failures. If an onboarding attempt is failing, the client log will contain the specific error code and allow verification of the correct log collection.

Why this answer

The Microsoft Defender for Endpoint client logs (option C) are the primary source for troubleshooting onboarding issues because they contain detailed records of the client's registration, communication with the cloud service, and policy application. If a device is not receiving security updates, it often indicates a failure in the onboarding process or a connectivity problem, which these logs directly capture. Checking these logs first allows you to verify the device's enrollment status and identify any errors in the initial connection or certificate exchange.

Exam trap

The trap here is that candidates often confuse 'security updates' with Windows Update logs (option D), but the question specifically targets Defender for Endpoint onboarding, which requires checking the client's own logs to confirm registration and communication with the cloud service.

How to eliminate wrong answers

Option A is wrong because Event Viewer Application logs record application-level events, not the specific onboarding or communication status of the Defender for Endpoint sensor. Option B is wrong because System logs focus on driver and hardware events, not the client-to-cloud registration process required for onboarding. Option D is wrong because Windows Update logs track update installation and download failures, but they do not indicate whether the device is properly enrolled in Defender for Endpoint; a device can be fully onboarded yet still have update issues unrelated to the security service.

156
MCQmedium

Your organization uses Microsoft Defender for Cloud Apps. You discover that a user is downloading large amounts of data from SharePoint Online to an unmanaged device. You need to automatically block the download and alert the security team. What should you configure?

A.Session policy
B.Access policy
C.File policy
D.Anomaly detection policy
AnswerA

Session policies apply real-time, in-session controls through Conditional Access app control, blocking downloads to unmanaged devices and raising alerts. This satisfies the requirement to automatically prevent the SharePoint Online download while notifying the security team.

Why this answer

A session policy in Defender for Cloud Apps applies real-time controls during a user session, including the ability to block downloads to unmanaged devices and trigger alerts. This is the correct control for stopping an active data exfiltration attempt from SharePoint Online.

Exam trap

The trap is confusing file policies (which scan content) with session policies (which enforce real-time controls), or picking anomaly detection which only alerts and does not block.

How to eliminate wrong answers

Option B is wrong because access policies control whether a user can sign in to an app at all, not what they can do once inside a session. Option C is wrong because file policies scan and classify files at rest or on upload, but they do not block real-time downloads in a session. Option D is wrong because anomaly detection policies flag unusual behavior (e.g., mass download) but do not enforce a block — they generate alerts only.

157
MCQhard

You are a security administrator for a company that uses Microsoft Defender XDR. You need to integrate Microsoft Defender XDR with Microsoft Sentinel to create a unified incident view. You want to ensure that incidents from Defender XDR are automatically created in Sentinel. What should you do?

A.In Microsoft Defender XDR settings, enable the Microsoft Sentinel integration and select the Sentinel workspace
B.Enable the Microsoft Defender XDR connector in Microsoft Sentinel and turn on incident creation
C.Configure a custom detection rule in Defender XDR that calls the Microsoft Sentinel API
D.Install the Microsoft Sentinel solution for Microsoft Defender XDR from the Content Hub
AnswerB

To integrate Defender XDR with Sentinel and have incidents automatically created in Sentinel, you must enable the Microsoft Defender XDR data connector in Sentinel and specifically turn on the option to create incidents from Defender XDR alerts. This establishes the bi-directional synchronization and ensures incidents appear in both portals.

Why this answer

Enabling the Microsoft Defender XDR connector in Microsoft Sentinel and turning on incident creation is the correct method to ensure incidents from Defender XDR are automatically created in Sentinel. This provides a unified incident view and enables Sentinel's SOAR capabilities on Defender XDR incidents.

Exam trap

The trap here is assuming that installing a solution or configuring settings in Defender XDR is sufficient, but the incident creation toggle is specifically in the Sentinel data connector configuration.

158
Multi-Selectmedium

Which THREE features are part of Microsoft Defender XDR? (Select THREE.)

Select 3 answers
A.Microsoft Purview
B.Microsoft Defender for Endpoint
C.Microsoft Defender for Office 365
D.Microsoft Sentinel
E.Microsoft Defender for Identity
AnswersB, C, E

Microsoft Defender for Endpoint contributes endpoint detection and response telemetry into the unified Microsoft Defender XDR portal, correlating device alerts with identity and email signals. It is one of the core workloads natively integrated into Microsoft Defender XDR, satisfying the stem's selection of three features.

Why this answer

Microsoft Defender XDR is a unified security solution that integrates signals from Microsoft Defender for Endpoint, Microsoft Defender for Office 365, Microsoft Defender for Identity, and others. The correct answers are B, C, and E. Option A (Microsoft Purview) is a data governance and compliance solution, not part of Defender XDR.

Option D (Microsoft Sentinel) is a separate cloud-native SIEM and SOAR solution.

159
MCQhard

Your organization uses Microsoft Defender for Endpoint. You need to configure a rule that automatically isolates a device from the network when a specific threat is detected, but only if the device is in a specific device group. Which approach should you use?

A.Indicator of compromise (IoC)
B.Automation rule
C.Custom detection rule
D.Group policy in Intune
AnswerB

An automation rule in Microsoft 365 Defender allows you to define conditions based on alert or incident properties and then automatically run a series of actions, including Microsoft Defender for Endpoint's isolate device response action. By specifying a condition like 'Alert severity' or 'Threat category,' you can trigger device isolation without manual intervention. Automation rules are the appropriate mechanism because they combine trigger conditions with remediation actions like isolation.

Why this answer

Automation rules in Microsoft Defender for Endpoint allow you to define automated actions, such as isolating a device, based on specific conditions like threat severity and device group membership. This directly meets the requirement to isolate only devices in a specific group when a specific threat is detected, as automation rules support granular scoping by device group.

Exam trap

The trap here is that candidates often confuse automation rules with custom detection rules, thinking custom detection rules can also trigger automated actions, but only automation rules provide the device group scoping and direct remediation actions like isolation.

How to eliminate wrong answers

Option A is wrong because Indicators of Compromise (IoCs) are used to detect or block known malicious entities (e.g., file hashes, IPs, URLs) but do not trigger automated response actions like device isolation based on device group membership. Option C is wrong because Custom Detection Rules are for creating custom alerts based on advanced hunting queries, not for configuring automated remediation actions like isolation; they can trigger alerts but not directly execute device isolation. Option D is wrong because Group Policy in Intune is used for device configuration and compliance policies, not for real-time automated response to threat detections in Defender for Endpoint.

160
MCQmedium

A company is planning to deploy Microsoft Defender for Endpoint to its Windows 10 devices. The devices are managed by Microsoft Intune. The security team wants to ensure that the MDE sensor is installed automatically on new devices that are enrolled in Intune. Which method should the team use?

A.Manually install MDE on each device.
B.Use Group Policy to deploy the MDE installation package.
C.Deploy MDE using Microsoft Configuration Manager.
D.Create an Endpoint security policy in Intune to deploy MDE.
AnswerD

Creating an Endpoint security policy in Intune deploys the MDE sensor automatically during enrolment, satisfying the requirement that new Windows 10 devices receive it without manual intervention. This built-in connector pushes the onboarding package to Intune-managed devices, unlike configuration profiles or scripts, which need extra packaging and assignment.

Why this answer

The correct method is to create an Endpoint security policy in Intune specifically for Microsoft Defender for Endpoint. This policy type allows you to configure the MDE onboarding blob and automatically deploy the MDE sensor to Windows 10 devices enrolled in Intune. It is the native, cloud-based approach that ensures new devices receive the sensor without manual intervention or on-premises infrastructure.

Exam trap

MS-102 often tests the misconception that Group Policy or Configuration Manager are required for automatic deployment, when in fact Intune's native Endpoint security policies are the recommended method for cloud-managed devices.

How to eliminate wrong answers

Option A is wrong because manual installation does not scale, is error-prone, and fails to meet the requirement for automatic deployment to new devices. Option B is wrong because Group Policy is an on-premises Active Directory tool that cannot natively target Intune-enrolled devices without hybrid Azure AD join and even then lacks direct integration for MDE onboarding in modern management. Option C is wrong because Microsoft Configuration Manager requires additional infrastructure, is not automatically available for Intune-managed devices, and is unnecessary when Intune can handle the deployment directly.

161
MCQeasy

You are a security administrator for a company that uses Microsoft Defender XDR. You need to investigate an incident that involves multiple alerts across different workloads. Which feature in Microsoft Defender XDR should you use to view the full attack story and related entities?

A.Incident details page
B.Advanced hunting
C.Threat analytics
D.Incident queue
AnswerA

The incident details page in Microsoft Defender XDR aggregates all alerts, entities, and automated investigations related to an incident. It provides a visual attack story, showing the sequence of events and relationships between entities, which is exactly what you need to investigate the incident.

Why this answer

The incident details page in Microsoft Defender XDR is designed to provide a comprehensive view of an incident, including all related alerts, entities, and the attack story. This allows security administrators to understand the full scope and progression of the attack.

Exam trap

The trap here is confusing the incident queue with the incident details page; the queue only lists incidents, while the details page provides the full story.

162
Multi-Selectmedium

You are configuring Microsoft Defender for Office 365. Which TWO actions should you take to protect users from phishing attacks that use impersonation?

Select 2 answers
A.Create a data loss prevention (DLP) policy to prevent sharing of credentials.
B.Configure anti-spam policies to increase the spam confidence level.
C.Configure anti-phishing policies to protect users from impersonation of custom domains.
D.Configure anti-phishing policies to protect users from impersonation of internal users.
E.Enable Safe Attachments for SharePoint, OneDrive, and Microsoft Teams.
AnswersC, D

In Defender for Office 365, an anti-phishing policy's impersonation settings let you specify custom domains to protect, and the service uses heuristics and machine learning to flag messages whose sending domain appears visually or logically similar to that protected domain. This mitigates attacks where an external sender uses a lookalike domain (e.g., typo-squatted or punycode variants) to trick users into thinking the mail originates from your organization. Because this is an identity-based detection, it is the correct policy category for the stated threat.

Why this answer

Option C is correct because anti-phishing policies in Microsoft Defender for Office 365 include impersonation settings that specifically protect against spoofing of custom domains the organization owns, using domain impersonation protection with actions like quarantining or moving messages to the Junk folder. Option D is also correct because the same anti-phishing policy provides user impersonation protection, which detects messages where the display name matches an internal user (such as executives or key staff) and applies the configured action. These two settings directly address phishing attacks that rely on impersonating trusted domains and internal users.

Option A is not correct because DLP policies govern sensitive information sharing, not impersonation-based phishing. Option B is not correct because raising the spam confidence level (SCL) affects bulk/spam filtering, not impersonation detection. Option E is not correct because Safe Attachments for SharePoint, OneDrive, and Teams protects against malicious files in those workloads, not impersonation phishing.

Exam trap

MS-102 often tests the confusion between anti-spam, anti-phishing, and Safe Attachments features, leading candidates to select spam confidence level adjustments or DLP instead of the specific impersonation settings in anti-phishing policies.

163
MCQmedium

Your organization uses Microsoft Defender XDR and Microsoft 365 E5 licenses. You are a security administrator. The security team wants to receive email notifications for high-severity incidents only. You need to configure the notification settings. What should you do?

A.In the Microsoft Defender XDR portal, go to Settings > Microsoft 365 Defender > Email notifications, and create a notification for high-severity incidents.
B.Create an incident response rule that sends an email when a high-severity incident is created.
C.Use the Microsoft Purview compliance portal to create an alert policy.
D.Configure a service health notification in the Microsoft 365 admin center.
AnswerA

Microsoft Defender XDR email notifications are configured under Settings > Microsoft 365 Defender > Email notifications, where you define the incident severity threshold. Creating a notification scoped to high severity delivers exactly the requested alerts, filtering out medium and low incidents.

Why this answer

In Microsoft Defender XDR, email notifications for incidents are configured under Settings > Microsoft 365 Defender > Email notifications. You can create a notification rule that specifies the severity level (e.g., high) and recipients. This directly fulfills the requirement to receive email notifications for high-severity incidents only.

Exam trap

MS-102 often tests the confusion between incident response rules (which automate actions) and email notification settings (which send emails), leading candidates to choose the wrong feature.

How to eliminate wrong answers

Option B is wrong because incident response rules are used to automate actions like assigning or tagging incidents, not to send email notifications; they cannot trigger emails. Option C is wrong because Microsoft Purview compliance portal alert policies are for compliance-related alerts (e.g., DLP, eDiscovery), not for Defender XDR incidents. Option D is wrong because service health notifications in the Microsoft 365 admin center inform about service outages and advisories, not security incidents.

164
Multi-Selectmedium

A security administrator is configuring Microsoft Defender for Cloud Apps to protect against data exfiltration from SaaS apps. The administrator wants to create a policy that alerts when a user attempts to download more than 50 files from SharePoint Online within 5 minutes. Which two components must be configured to achieve this? (Choose two.)

Select 2 answers
A.File policy
B.Session policy
C.Activity policy
D.Conditional Access App Control
E.App connector for SharePoint Online
AnswersC, E

An activity policy in Microsoft Defender for Cloud Apps evaluates user activities against repeat-activity and threshold criteria, such as more than 50 downloads within 5 minutes. It satisfies the stem's alerting requirement by triggering on the defined SharePoint Online download pattern.

Why this answer

The correct answers are C (Activity policy) and E (App connector for SharePoint Online). An activity policy is needed to define the threshold (50 files in 5 minutes) and trigger an alert when exceeded. The app connector for SharePoint Online must be enabled to allow Defender for Cloud Apps to monitor SharePoint activity.

Option A (File policy) is incorrect because file policies govern file sharing and collaboration, not download counts. Option B (Session policy) is used for real-time session control, not alerting on activity counts. Option D (Conditional Access App Control) is used to enforce access policies, not for monitoring specific activities.

165
MCQmedium

A security administrator wants to automatically block malicious IP addresses from sending email to Exchange Online mailboxes. Which Microsoft Defender component should be configured?

A.Exchange Online Protection (EOP)
B.Microsoft Defender for Endpoint
C.Microsoft Defender for Identity
D.Microsoft Defender for Cloud Apps
AnswerA

Exchange Online Protection (EOP) is the correct answer because its connection filtering feature evaluates the source IP address of every inbound SMTP connection against Microsoft's default and tenant-specific IP allow/block lists and real-time reputation data. Malicious IPs are rejected at the transport layer before the message is accepted, and admins can explicitly add IPs to the block list in the anti-spam policy to enforce a custom allow/deny set for inbound mail flow.

Why this answer

Exchange Online Protection (EOP) is the cloud-based email filtering service that protects Exchange Online mailboxes from spam, malware, and malicious IP addresses. It includes connection filtering, which can automatically block messages from specified IP addresses by using the default connection filter policy or custom IP Allow/Block lists. This makes EOP the correct component for blocking malicious IPs from sending email to Exchange Online.

Exam trap

The trap here is that candidates may confuse Microsoft Defender for Endpoint (which handles device-level threats) with email security, or assume that Defender for Cloud Apps (a CASB) can filter inbound email, when in fact only EOP provides the connection filtering and IP block list functionality for Exchange Online mail flow.

How to eliminate wrong answers

Option B (Microsoft Defender for Endpoint) is wrong because it focuses on endpoint detection and response (EDR) for devices, not email traffic filtering or IP-based blocking for Exchange Online. Option C (Microsoft Defender for Identity) is wrong because it monitors on-premises Active Directory for identity-based threats (e.g., lateral movement, privilege escalation), not inbound email from IP addresses. Option D (Microsoft Defender for Cloud Apps) is wrong because it provides cloud access security broker (CASB) capabilities for SaaS applications, including shadow IT discovery and app permissions, but does not directly block IP addresses from sending email to Exchange Online.

166
MCQmedium

You are a security administrator for a company that uses Microsoft Defender XDR. A security incident involving a compromised user account has been escalated. You need to identify all devices where the compromised user account signed in within the last 7 days. Which Microsoft Defender XDR feature should you use?

A.Incident queue filtered by the user's email address
B.Device inventory filtered by the user's primary email
C.Advanced hunting with the IdentityLogonEvents table
D.Microsoft Defender for Cloud Apps activity log
AnswerC

The IdentityLogonEvents table in advanced hunting contains sign-in events from Microsoft Defender for Identity, providing details such as the user account, device name, and timestamp. Querying this table for the compromised user over the last 7 days will list all devices where that account signed in, directly answering the requirement.

Why this answer

Advanced hunting with the IdentityLogonEvents table provides a comprehensive view of sign-in events across devices, including those from Defender for Identity. By querying this table for the compromised user and a 7-day timeframe, you can accurately list all devices where the account signed in, enabling effective incident response.

Exam trap

The trap here is assuming that incident queue or device inventory can provide a complete list of sign-in events, but they lack the granular logon data needed for this investigation.

167
MCQhard

Your organization has deployed Microsoft Defender for Cloud Apps. You want to detect anomalous behavior such as impossible travel for users accessing cloud apps. You need to configure the appropriate policy. Which policy type should you create?

A.App discovery policy
B.Activity policy
C.Session policy
D.File policy
AnswerB

Activity policies evaluate user activity events against behavioural baselines, so impossible travel and other anomalies trigger alerts or governance actions. They operate on the activity log rather than file content, matching the requirement to detect anomalous cloud app access.

Why this answer

Activity policies in Microsoft Defender for Cloud Apps are designed to monitor user activity across cloud apps and trigger alerts or governance actions on anomalous behavior, including impossible travel, suspicious IP addresses, and unusual file downloads. Creating an activity policy with the 'Impossible travel' template directly detects the scenario described. This is the correct policy type for behavioral anomaly detection.

Exam trap

MS-102 often tests the confusion between activity policies (behavioral anomaly detection) and session policies (real-time access control), so candidates pick session policy when the question mentions 'anomalous behavior'.

How to eliminate wrong answers

Option A is wrong because app discovery policies identify shadow IT and unsanctioned cloud apps from traffic logs — they don't detect user behavior anomalies like impossible travel. Option C is wrong because session policies apply conditional access and real-time session controls (e.g., block download) for sanctioned apps, not anomaly detection. Option D is wrong because file policies scan and classify files for DLP or malware, not user travel anomalies.

168
MCQmedium

A security administrator wants to configure Automated Investigation and Response (AIR) in Microsoft 365 Defender to automatically isolate a device when a high-severity alert for malware is detected. Which step is required?

A.A: Create an automation rule in Microsoft Sentinel.
B.B: Create a custom detection rule in advanced hunting.
C.C: Configure the device to be part of a device group and enable automation level.
D.D: Enable auto-removal of malware from devices.
AnswerC

To actually turn on AIR, you place the device into a device group in Microsoft 365 Defender (under Endpoints > Device groups) and select an automation level such as 'Full - remediate threats automatically' or 'Automatic - investigate threats automatically.' The device group's automation level decides whether AIR runs automatically and what actions (isolation, file removal, etc.) can be taken without approval. Without a proper device group with the desired automation level, AIR's automatic actions remain disabled or require manual approval.

Why this answer

To enable Automated Investigation and Response (AIR) in Microsoft Defender for Endpoint, the device must be added to a device group, and the automation level for that group must be set to 'Full – remediate threats automatically' or a similar level. This configuration allows Defender to automatically isolate a device when a high-severity malware alert is triggered, as part of the built-in AIR playbooks.

Exam trap

The trap here is that candidates often confuse Microsoft Sentinel automation rules (which are for cross-source orchestration) with the device group automation settings in Microsoft Defender for Endpoint, leading them to pick Option A instead of the correct device group configuration.

How to eliminate wrong answers

Option A is wrong because Microsoft Sentinel automation rules are used for orchestration and response across multiple data sources, not for configuring device-level automated isolation in Microsoft Defender for Endpoint. Option B is wrong because custom detection rules in advanced hunting are for creating custom alerts based on KQL queries, not for enabling automated response actions like device isolation. Option D is wrong because 'auto-removal of malware' is not a configurable setting in Defender for Endpoint; remediation actions are controlled via automation levels and device groups, not a separate toggle.

169
MCQhard

A security administrator wants to prevent malware from using Office macros to spawn malicious processes. Specifically, they want to block Excel, Word, and PowerPoint from creating child processes. Which Microsoft Defender for Endpoint capability should be configured?

A.Threat & Vulnerability Management
B.Attack Surface Reduction (ASR) rules
C.Web Protection
D.Network Protection
AnswerB

Attack Surface Reduction (ASR) rules are the correct control because they specifically target common attack techniques, including the rule 'Block Office applications from creating child processes.' This rule, identified by GUID e6db97e8-5c6a-4b3f-b3a4-6c3e2f3d4e5f (actual GUID: d4f6c3e7-4c1a-4f2b-9a5b-9d3f2a1c6b4e), uses behavior-based monitoring to prevent Office executables like WINWORD.EXE or EXCEL.EXE from launching other processes such as PowerShell or cmd.exe. This directly stops macro malware from executing its payload, including zero-day variants that no signature would catch.

Why this answer

Attack Surface Reduction (ASR) rules are a Microsoft Defender for Endpoint capability specifically designed to block common malware behaviors, such as Office applications (Excel, Word, PowerPoint) from creating child processes. This rule (GUID: 26190899-1602-49e8-8b27-eb1d0a1ce869) prevents macros from spawning cmd.exe, powershell.exe, or other executables, directly addressing the administrator's requirement.

Exam trap

The trap here is that candidates often confuse Attack Surface Reduction rules with other Defender for Endpoint capabilities like Network Protection or Web Protection, mistakenly thinking that blocking network traffic is equivalent to blocking local process creation, when ASR rules are the only option that directly controls child process spawning from Office apps.

How to eliminate wrong answers

Option A is wrong because Threat & Vulnerability Management (TVM) identifies, prioritizes, and remediates vulnerabilities in software and configurations, but it does not enforce runtime behavioral blocks like preventing child process creation. Option C is wrong because Web Protection blocks access to malicious URLs, IPs, and web content, but it does not control local process spawning from Office macros. Option D is wrong because Network Protection blocks outbound connections to malicious domains or IPs at the network layer, but it does not prevent local child process creation from Office applications.

170
MCQmedium

You are a Microsoft 365 administrator for a company that uses Microsoft Defender for Cloud Apps. The security team wants to detect when users download a large number of files from SharePoint Online in a short period, which could indicate data exfiltration. You need to create a policy to alert on this activity. What should you do?

A.Set up an anomaly detection policy for unusual file access.
B.Create an activity policy with a filter for 'Download file' and a threshold for the number of files.
C.Configure a session policy to block downloads from SharePoint Online.
D.Create a file policy with a filter for file name and a threshold for file size.
AnswerB

Activity policies in Microsoft Defender for Cloud Apps monitor user activities across connected apps. By filtering for 'Download file' and setting a threshold on the number of files within a time window, you can detect mass download behavior indicative of exfiltration. This directly addresses the requirement.

Why this answer

Activity policies in Microsoft Defender for Cloud Apps are designed to monitor user activities and can be configured with filters and thresholds to detect specific behaviors like mass file downloads. This provides the precise alerting needed for potential data exfiltration.

Exam trap

The trap here is assuming that file policies or session policies can detect download volume, but only activity policies track user actions with customizable thresholds.

171
MCQhard

An administrator deployed the above Intune device configuration policy for Microsoft Defender for Endpoint on Windows 10 devices. Users report that some potentially unwanted applications (PUA) are still being installed. What is the most likely cause?

A.The cloud timeout value is too low, causing PUA detection to fail.
B.The PUAProtection setting is in AuditMode and not blocking PUAs.
C.Cloud-delivered protection is set to High level, which does not affect PUAs.
D.Real-time monitoring is disabled.
AnswerB

The PUAProtection setting in AuditMode instructs Microsoft Defender Antivirus to detect potentially unwanted applications and record them in the event log without taking any blocking action. Because AuditMode is only logging findings, users can still install and run PUAs, making this setting the direct cause of the observed behavior. To actually block PUAs, PUAProtection must be set to Enable or Block mode.

Why this answer

The PUAProtection setting in the Defender for Endpoint Intune policy has three modes: Off, AuditMode, and Enabled (Block). AuditMode only logs detections without blocking, so PUAs continue to install. To actually block PUAs, the setting must be set to 'Enabled' (Block), not AuditMode.

Exam trap

The trap is that AuditMode sounds like it still takes action (auditing implies monitoring), so candidates assume PUAs are being detected and blocked — but AuditMode is explicitly non-blocking, which is the exact symptom described.

How to eliminate wrong answers

Option A is wrong because cloud timeout values govern how long the endpoint waits for a cloud protection verdict before falling back to local decision — they do not cause PUA detection to fail outright, and PUA blocking is a separate policy setting. Option C is wrong because cloud-delivered protection level (High/Normal/Zero-tolerance) affects the aggressiveness of cloud-based malware blocking, not PUA enforcement; PUA blocking is controlled by the dedicated PUAProtection setting. Option D is wrong because real-time monitoring being disabled would broadly weaken all protection, but the question specifically describes PUAs still installing despite a policy — the direct cause is the PUAProtection mode, not real-time monitoring.

172
MCQeasy

Your organization uses Microsoft Defender for Office 365. You need to ensure that all email messages containing encrypted attachments are automatically scanned for malware before delivery. What should you configure?

A.Safe Attachments policy
B.Safe Links policy with URL scanning
C.Anti-malware policy
D.Anti-spam policy
AnswerA

Dynamic Delivery allows scanning encrypted attachments.

Why this answer

Safe Attachments policy can be configured to scan encrypted attachments. Option B is wrong because it is for scanning URLs in emails. Option C is wrong because the anti-malware policy handles malware detection but does not specifically address encrypted attachments.

Option D is wrong because the anti-spam policy is designed to filter spam, not to scan attachments for malware.

173
MCQmedium

Your organization uses Microsoft Defender for Office 365. Users report that legitimate emails from a specific partner domain are being moved to Junk Email folder. You verify that the partner's SPF, DKIM, and DMARC records are correctly configured. Which two actions should you take to resolve this issue?

A.Modify the Anti-Spam policy to increase the spam threshold.
B.Review the Anti-Phishing policy's spoof intelligence settings.
C.Configure the Outbound spam filter policy.
D.Disable the Spam filter for the affected users.
E.Add the partner domain to the Tenant Allow/Block List as an allowed domain.
AnswerB, E

Spoof intelligence settings can flag the partner domain as intra-organisation or impersonating a trusted sender, overriding correct SPF, DKIM and DMARC. Reviewing them identifies why legitimate mail is treated as spoofed and routed to Junk Email.

Why this answer

Legitimate emails from a partner domain are being moved to Junk Email folder despite correct SPF, DKIM, and DMARC records. This typically indicates that the emails are being misclassified as spoofed or phishing. Reviewing the Anti-Phishing policy's spoof intelligence settings (Option B) allows you to check if the partner domain is being incorrectly treated as a spoof sender and adjust the settings accordingly.

Additionally, adding the partner domain to the Tenant Allow/Block List as an allowed domain (Option E) explicitly permits emails from that domain, overriding any false positive filtering. Option A (increasing spam threshold) may reduce spam filtering effectiveness and does not address the root cause. Option C (Outbound spam filter policy) affects outgoing emails, not inbound.

Option D (disabling spam filter) is too aggressive and removes protection for the affected users. Therefore, the correct actions are B and E.

174
Multi-Selecthard

Your organization uses Microsoft Defender for Cloud Apps. You need to create a policy that detects when a user signs in from an unknown IP address and then downloads a large number of files. Which THREE components should you configure?

Select 3 answers
A.IP address range category
B.Scope (users and groups)
C.Anomaly detection policy template
D.Session policy
E.Alert settings
AnswersB, C, E

The Scope (users and groups) component is a mandatory and correct part of an anomaly detection policy in Microsoft Defender for Cloud Apps. It defines the set of users or groups whose activity is monitored and evaluated against the detection template. For example, you can scope the policy to only your global administrators or a specific group of high-privilege users, which reduces false positives and focuses on the accounts that matter most. Without a defined scope, the policy cannot determine whose activities are subject to anomaly analysis.

Why this answer

The policy must be scoped to specific users or groups to ensure that the anomaly detection rule (unknown IP followed by mass download) applies only to the intended set of accounts. Without scoping, the policy would evaluate all users, which may generate excessive noise or miss targeted monitoring. In Microsoft Defender for Cloud Apps, the Scope (users and groups) setting is a required component when creating an anomaly detection policy to define which identities are monitored.

Exam trap

The trap here is that candidates often confuse the IP address range category (Option A) as a required component for defining unknown IPs in an anomaly detection policy, when in fact the policy automatically uses the organization's configured IP ranges and does not require a separate category to be selected during policy creation.

175
MCQeasy

Refer to the exhibit. You deploy this configuration profile to Windows devices. What is the most likely outcome?

A.Automated investigation will be triggered for alerts with severity Medium and above, and email notifications will be sent to admin@contoso.com.
B.Automated investigation will be triggered only for alerts with severity High, and email notifications will be sent to all admins.
C.Automated investigation will be disabled, and email notifications will be sent to admin@contoso.com.
D.Automated investigation will be triggered for all alerts regardless of severity, and no email notifications will be sent.
AnswerA

This configuration profile is correctly interpreted because it explicitly sets the automated investigation severity threshold to 'Medium and above', meaning alerts classified as Medium, High, or Critical will trigger an automated investigation. Additionally, email notifications are enabled and addressed specifically to admin@contoso.com, not to all administrators, which matches the 'To' field in the policy. The combination of an inclusive severity threshold and a targeted recipient list is exactly what the deployment produces.

Why this answer

The configuration profile sets the automated investigation action to 'Medium or higher' and specifies a single email recipient (admin@contoso.com). This means Defender for Endpoint will trigger automated investigations for alerts with severity Medium, High, or Critical, and send email notifications only to the listed address, not to all admins.

Exam trap

The trap here is that candidates often confuse the severity filter with a binary on/off toggle, or assume that specifying a single email recipient sends notifications to all admins by default, when in fact the recipient list is explicitly defined.

How to eliminate wrong answers

Option B is wrong because the profile sets the severity threshold to 'Medium or higher', not 'High' only, and notifications are sent to the specified address, not all admins. Option C is wrong because automated investigation is not disabled; the profile explicitly enables it with a severity filter. Option D is wrong because the profile restricts automated investigation to alerts of Medium severity and above, not all alerts, and it does specify email notifications to admin@contoso.com.

176
MCQeasy

You need to configure Microsoft Defender for Cloud Apps to detect anomalous user behavior such as impossible travel. Which type of policy should you create?

A.Access policy
B.Session policy
C.Anomaly detection policy
D.File policy
AnswerC

Anomaly detection policies in Microsoft Defender for Cloud Apps baseline each user's normal activity and raise alerts on deviations such as impossible travel, satisfying the requirement to detect anomalous behaviour. Unlike activity policies, which trigger on predefined matching criteria, they use behavioural analytics, so no manual rule logic is needed.

Why this answer

Anomaly detection policy. In Microsoft Defender for Cloud Apps, anomaly detection policies are specifically designed to identify unusual user behaviors, such as impossible travel (login from geographically distant locations within a short time), unusual activity patterns, and other security anomalies. Option A (Access policy) is incorrect because it enforces access controls based on conditions like location or device, rather than detecting anomalies.

Option B (Session policy) is incorrect as it monitors and controls real-time application sessions, not anomaly detection. Option D (File policy) is incorrect because it focuses on data protection by applying rules to files stored in cloud apps.

177
MCQeasy

A security administrator needs a single console to investigate and respond to a complex incident involving alerts from endpoints, email, and identities. Which Microsoft portal should they use?

A.Microsoft 365 Defender portal
B.Microsoft Sentinel
C.Microsoft Defender for Cloud
D.Microsoft 365 compliance center
AnswerA

Microsoft 365 Defender portal unifies signals from Defender for Endpoint, Defender for Office 365, and Microsoft Entra ID Protection into one incident view, enabling cross-domain investigation and response. This single console satisfies the requirement to correlate endpoint, email, and identity alerts for a complex incident.

Why this answer

The Microsoft 365 Defender portal (security.microsoft.com) is the correct choice because it provides a unified incident management console that correlates alerts from Microsoft Defender for Endpoint, Microsoft Defender for Office 365, and Microsoft Defender for Identity. This allows the security administrator to investigate and respond to a complex incident spanning endpoints, email, and identities from a single pane of glass, leveraging automated investigation and response (AIR) capabilities.

Exam trap

The trap here is that candidates often confuse Microsoft Sentinel (a SIEM) with the Microsoft 365 Defender portal (an XDR console), assuming that any security investigation must go through a SIEM, but the question specifically asks for the single console that natively correlates alerts from endpoints, email, and identities without additional data ingestion setup.

How to eliminate wrong answers

Option B is wrong because Microsoft Sentinel is a cloud-native SIEM/SOAR platform that ingests logs from multiple sources, but it is not the single console designed for native XDR incident correlation across Microsoft 365 Defender workloads; it requires additional configuration and data connectors to unify alerts from endpoints, email, and identities. Option C is wrong because Microsoft Defender for Cloud is focused on securing cloud workloads (IaaS, PaaS, and data services) and does not natively integrate email and identity alerts from Microsoft 365 Defender. Option D is wrong because the Microsoft 365 compliance center is designed for data governance, eDiscovery, and compliance management, not for real-time security incident investigation and response.

178
MCQeasy

Your organization uses Microsoft Defender for Cloud Apps. You need to create a policy that alerts when a user downloads more than 10 files from SharePoint Online within 10 minutes. This activity should be considered anomalous. Which type of policy should you create?

A.Cloud Discovery policy
B.Activity policy
C.Session policy
D.App discovery policy
AnswerB

Activity policies in Microsoft Defender for Cloud Apps evaluate user activity against thresholds and anomaly detection, so a rule triggering when more than ten SharePoint Online downloads occur within ten minutes matches this policy type.

Why this answer

An Activity policy in Defender for Cloud Apps triggers alerts based on user activities such as file downloads, and supports thresholds and time windows. To alert when a user downloads more than 10 files from SharePoint Online within 10 minutes, you configure an Activity policy with the 'Download file' activity, a threshold of 10, and a 10-minute window. This matches the requirement exactly.

Exam trap

MS-102 often tests whether candidates confuse Activity policies (threshold-based alerts on user actions) with Session policies (real-time access control) or Cloud Discovery policies (shadow IT visibility).

How to eliminate wrong answers

Option A is wrong because a Cloud Discovery policy governs shadow IT discovery from traffic logs, not user activity thresholds. Option C is wrong because a Session policy controls real-time session actions (block, protect, proxy) via Conditional Access App Control, not alerting on download counts. Option D is wrong because App discovery policy is another name for Cloud Discovery, focused on identifying unsanctioned apps.

179
Multi-Selecthard

You are a security administrator for Fabrikam, Inc. The company uses Microsoft Defender XDR with Microsoft Defender for Identity, Microsoft Defender for Endpoint, and Microsoft Defender for Cloud Apps onboarded. An analyst is investigating a suspected pass-the-hash attack against a domain controller. The analyst needs to correlate identity signals with device and cloud app activity in the unified incident. You must identify which Defender XDR capabilities the analyst can use to pivot from an identity alert to related device and cloud activity. (Choose two.)

Select 2 answers
A.Run Advanced Hunting queries against the IdentityLogonEvents and DeviceLogonEvents tables in the Microsoft 365 Defender portal.
B.Use the incident graph in the Microsoft 365 Defender portal to expand the alert and view related entities such as accounts, devices, and IP addresses.
C.Use the Microsoft Defender for Endpoint device timeline to review process creation events on the targeted domain controller.
D.Use the Microsoft Defender for Cloud Apps activity log to review file downloads from sanctioned cloud applications.
E.Use the Microsoft Defender for Identity health alerts page to review sensor configuration issues on the domain controllers.
AnswersA, B

Advanced Hunting exposes Kusto tables from all onboarded Defender workloads, including IdentityLogonEvents for Defender for Identity and DeviceLogonEvents for Defender for Endpoint. Joining these tables allows the analyst to correlate identity logon anomalies with device logon activity and identify lateral movement associated with a pass-the-hash attack.

Why this answer

Cross-domain correlation in Microsoft Defender XDR is achieved through the unified incident graph and through Advanced Hunting across the Kusto tables exposed by each onboarded workload. The graph links accounts, devices, IP addresses, and cloud apps, while Advanced Hunting allows joining IdentityLogonEvents with DeviceLogonEvents to trace pass-the-hash lateral movement. Health alerts, cloud app activity logs, and device timelines each cover only one domain.

Exam trap

The trap here is treating single-workload consoles or health pages as if they provide unified cross-domain correlation, when only the incident graph and Advanced Hunting span all onboarded workloads.

180
MCQhard

You are a security administrator for a large enterprise with 10,000 users. The company uses Microsoft 365 E5 licenses, which include Microsoft Defender XDR. The company has recently experienced a series of ransomware attacks where attackers gained initial access through phishing emails, then moved laterally using compromised credentials, and finally deployed ransomware on file servers. The CISO wants to implement a comprehensive defense strategy that reduces the attack surface and automates response. The requirements are: 1) Prevent phishing emails from reaching users, especially those targeting executives. 2) Detect and block lateral movement using compromised credentials. 3) Automatically contain compromised devices during an incident. 4) Provide a unified incident view across email, endpoints, and identities. You need to recommend a solution that meets all requirements with minimal manual effort. What should you do?

A.Configure Microsoft Defender XDR by enabling Defender for Office 365 with anti-phish and impersonation protection, Defender for Identity, and Defender for Endpoint with automated investigation and response.
B.Use Microsoft Purview to classify and protect sensitive data, and configure data loss prevention policies to block ransomware.
C.Deploy Microsoft Sentinel and create analytics rules to detect phishing, lateral movement, and ransomware. Configure automated playbooks to contain devices.
D.Upgrade to Microsoft Entra ID P2 and enable Identity Protection for risky sign-ins and user risk. Use Conditional Access to block access from compromised devices.
AnswerA

This is the correct approach because Microsoft Defender XDR unifies email, identity, and endpoint signals into a single incident pipeline. Defender for Office 365's anti-phishing and impersonation protection blocks malicious messages at the transport layer, Defender for Identity detects Kerberoasting, pass-the-hash, and other lateral movement techniques using Active Directory signals, and Defender for Endpoint's automated investigation and response can isolate endpoints and remediate ransomware artifacts. Correlating these alerts in the XDR incident view lets you see the full attack chain and contain it before broad encryption occurs.

Why this answer

Option A is correct because it leverages the native Microsoft Defender XDR suite, which directly addresses all four requirements: Defender for Office 365 with anti-phish and impersonation protection prevents phishing emails (requirement 1); Defender for Identity detects lateral movement using compromised credentials by monitoring on-premises Active Directory signals (requirement 2); Defender for Endpoint with automated investigation and response automatically contains compromised devices (requirement 3); and the integrated Defender XDR portal provides a unified incident view across email, endpoints, and identities (requirement 4). This solution requires minimal manual effort because the components are natively integrated and automation is built-in.

Exam trap

MS-102 often tests the misconception that Microsoft Sentinel or Purview alone can provide comprehensive XDR capabilities, when in fact Defender XDR is the integrated solution that natively meets prevention, detection, and automated response requirements with minimal manual effort.

How to eliminate wrong answers

Option B is wrong because Microsoft Purview focuses on data classification, protection, and DLP, which are reactive data-centric controls and do not prevent phishing emails, detect lateral movement, or automatically contain devices. Option C is wrong because Microsoft Sentinel is a SIEM/SOAR solution that requires custom analytics rules and playbooks, which demands significant manual configuration and tuning, and it does not natively provide the integrated prevention and automated containment across email, endpoints, and identities that Defender XDR offers out-of-the-box. Option D is wrong because Entra ID P2 and Identity Protection only address identity risks (risky sign-ins and users) and Conditional Access can block access but does not prevent phishing emails, detect lateral movement on-premises, or automatically contain compromised devices.

181
Multi-Selectmedium

You are a security administrator for a company that uses Microsoft Defender XDR. You need to configure alert policies to notify the security team when specific activities occur. You want to receive notifications for alerts related to malicious file detection and suspicious sign-in attempts. Which two actions should you perform? (Choose two.)

Select 2 answers
A.Set up a Microsoft Sentinel playbook.
B.Create a data loss prevention (DLP) policy.
C.Configure email notifications for the alert policy.
D.Create an alert policy in Microsoft 365 Defender with the appropriate detection sources.
E.Enable audit logging in Microsoft Purview compliance portal.
AnswersC, D

Configuring email notifications for the alert policy ensures that the security team is notified when the specified alerts are triggered. This step is essential to actually receive the notifications for malicious file detection and suspicious sign-in attempts, as the policy alone does not send emails.

Why this answer

To receive notifications for specific alerts in Microsoft Defender XDR, you must create an alert policy that includes the relevant detection sources and then configure email notifications for that policy. These two actions together ensure the security team is alerted about malicious files and suspicious sign-ins.

Exam trap

The trap here is thinking that enabling audit logging or creating DLP policies will generate the required alerts, when they serve different purposes.

182
MCQmedium

Refer to the exhibit. What is the effect of this session policy?

A.Allows viewing but blocks downloading files on managed devices
B.Blocks all access to SharePoint and OneDrive from unmanaged native clients only
C.Blocks upload of files to SharePoint Online and OneDrive from unmanaged devices
D.Blocks download of files from SharePoint Online and OneDrive on unmanaged devices
AnswerD

This session policy is configured for SharePoint Online and OneDrive to block the download action when access comes from an unmanaged device. It allows other actions like viewing, editing, and uploading, so user productivity is maintained while sensitive files cannot be saved locally on non-compliant devices. The restriction is enforced across both browser and native client access methods.

Why this answer

The session policy shown in the exhibit is configured to block downloads from SharePoint Online and OneDrive for unmanaged devices. This is achieved by applying a conditional access policy that targets unmanaged devices and restricts the download action specifically, while still allowing view-only access. The correct answer is D because the policy explicitly blocks the download of files, not uploads or all access.

Exam trap

The trap here is that candidates often confuse 'block downloads' with 'block all access' or 'block uploads,' leading them to select options B or C instead of recognizing that the policy specifically targets the download action only.

How to eliminate wrong answers

Option A is wrong because the policy blocks downloads on unmanaged devices, not managed devices; managed devices are typically allowed full access. Option B is wrong because the policy does not block all access to SharePoint and OneDrive; it only blocks downloads, and it applies to unmanaged devices, not just native clients. Option C is wrong because the policy blocks downloads, not uploads; uploads are still permitted on unmanaged devices.

183
MCQeasy

Your organization uses Microsoft Defender XDR. You need to configure automatic attack disruption for SaaS applications. Which Microsoft 365 security solution provides this capability?

A.Microsoft Defender for Identity
B.Microsoft Defender for Cloud Apps
C.Microsoft Defender for Office 365
D.Microsoft Defender for Endpoint
AnswerB

Microsoft Defender for Cloud Apps delivers automatic attack disruption for SaaS apps by correlating signals from Microsoft Entra ID and Defender XDR to identify compromised sessions or malicious OAuth apps, then containing the threat mid-attack. This satisfies the stem's requirement for a Microsoft 365 security solution providing SaaS-specific disruption.

Why this answer

Microsoft Defender for Cloud Apps (Option B) provides automatic attack disruption for SaaS applications by using risk indicators and automation to stop attacks in real time. Option A (Microsoft Defender for Identity) focuses on on-premises Active Directory and identity threats, not SaaS apps. Option C (Microsoft Defender for Office 365) protects email and collaboration tools.

Option D (Microsoft Defender for Endpoint) secures endpoints like desktops and servers. Therefore, only option B delivers the required capability.

Exam trap

Candidates often confuse Microsoft Defender for Cloud Apps with other Defender products. Remember that automatic attack disruption for SaaS is unique to Defender for Cloud Apps.

184
Multi-Selecthard

You are configuring Microsoft Defender for Identity. Which THREE capabilities does it provide?

Select 3 answers
A.Scanning of email attachments for malware.
B.Detection of compromised accounts through behavioral analytics.
C.Detection of reconnaissance activities such as LDAP enumeration.
D.Creation of data loss prevention (DLP) policies.
E.Detection of lateral movement between domain-joined machines.
AnswersB, C, E

Detection of compromised accounts through behavioral analytics is a core Defender for Identity feature. It establishes baselines for users and machines, then uses machine learning to flag anomalies such as impossible travel, unusual logon hours, or abnormal service usage. Once an account's behavior deviates from its profile, the sensor raises an alert, enabling investigation and remediation of the compromise.

Why this answer

Options B, C, and E are correct because Microsoft Defender for Identity provides detection of compromised accounts through behavioral analytics (B), detection of reconnaissance activities such as LDAP enumeration (C), and detection of lateral movement between domain-joined machines (E). Option A is incorrect because scanning email attachments for malware is a feature of Microsoft Defender for Office 365, not Defender for Identity. Option D is incorrect because creation of data loss prevention (DLP) policies is a feature of Microsoft Purview, not Defender for Identity.

185
MCQmedium

You are investigating a phishing campaign targeting your organization. In Microsoft Defender XDR, you run a KQL query in Advanced Hunting to find all email messages that contain a specific phishing URL. Which table should you query?

A.EmailUrlInfo
B.EmailAttachmentInfo
C.UrlClickEvents
D.EmailEvents
AnswerA

In Advanced hunting, EmailUrlInfo is the table that stores URL entities extracted from email messages, with each record tied to a specific email via NetworkMessageId. When investigating a phishing campaign, you use this table to search for messages containing a malicious URL or to pivot from a known email to all its embedded links. It also includes the URL's disposition (e.g., Phish) from Microsoft's threat reputation systems, making it the correct source for email-level URL information.

Why this answer

The EmailUrlInfo table in Advanced Hunting stores URL information extracted from email messages, including the specific URLs found in the body or attachments. To find all email messages containing a specific phishing URL, you must query this table because it directly maps URLs to their associated email identifiers (e.g., NetworkMessageId).

Exam trap

The trap here is that candidates confuse UrlClickEvents (which tracks user interaction after delivery) with EmailUrlInfo (which captures URL presence in the email itself), leading them to choose the wrong table for identifying messages containing a URL.

How to eliminate wrong answers

Option B is wrong because EmailAttachmentInfo stores metadata about email attachments (e.g., file names, hashes) but does not contain URL data. Option C is wrong because UrlClickEvents logs user clicks on URLs in emails or documents, not the presence of URLs in the email itself. Option D is wrong because EmailEvents contains high-level email delivery and flow data (e.g., sender, recipient, delivery status) but does not include the actual URL content.

186
MCQmedium

A security administrator needs to block outbound network connections from a compromised Windows device to a known malicious IP address. The solution should be configured in Microsoft Defender for Endpoint and must work at the network layer, not relying on a user-installed client. Which feature should the administrator enable?

A.Attack surface reduction (ASR) rules
B.Custom detection rules (advanced hunting)
C.Network protection
D.Web protection (web threat protection)
AnswerC

Network protection in Microsoft Defender for Endpoint works at the network layer and is specifically designed to block outbound connections to malicious domains, IP addresses, and URLs. It intercepts traffic from applications and the OS, inspecting connections against Microsoft's cloud-based threat intelligence feed, and if a match is found, the connection is dropped and a warning is shown to the user. In the context of a compromised Windows device, this provides the necessary automatic blocking of outbound callbacks to attacker-controlled infrastructure. It can also be deployed in block mode or audit mode, and when enabled it leverages the Windows Filtering Platform rather than only DNS-based filtering, so direct IP connections are covered.

Why this answer

Network protection, is correct because it is a Microsoft Defender for Endpoint feature that blocks outbound connections to malicious IP addresses and domains at the network layer, using the Windows Filtering Platform (WFP) to enforce policies without requiring a user-installed client. This ensures the block applies system-wide, even if the device is compromised, as it operates before the TCP/IP stack processes the connection.

Exam trap

The trap here is that candidates often confuse Network protection with Web protection, mistakenly thinking Web protection can block IP-based outbound connections, when in fact Web protection only filters HTTP/HTTPS traffic based on URL reputation and does not operate at the network layer for arbitrary IP addresses.

How to eliminate wrong answers

Option A is wrong because Attack surface reduction (ASR) rules are designed to block specific behaviors (e.g., script execution, Office macro abuse) at the endpoint, not to block outbound network connections to a specific IP address. Option B is wrong because Custom detection rules (advanced hunting) only create alerts based on queries against telemetry data; they do not actively block network traffic. Option D is wrong because Web protection (web threat protection) focuses on blocking malicious URLs and web content based on reputation, not on blocking outbound connections to a known malicious IP address at the network layer.

187
MCQmedium

A security analyst needs to search for devices that have been communicating with a known malicious command-and-control server over the past 7 days. The analyst wants to identify the process that initiated the connection. Which advanced hunting query would be most efficient?

A.DeviceNetworkEvents | where RemoteIP == 'malicious IP' and Timestamp > ago(7d) | project DeviceName, InitiatingProcessFileName, Timestamp
B.DeviceProcessEvents | where ProcessId in (select ProcessId from DeviceNetworkEvents where RemoteIP == 'malicious IP' and Timestamp > ago(7d)) | project DeviceName, ProcessFileName, Timestamp
C.DeviceNetworkEvents | where Timestamp > ago(7d) | join DeviceProcessEvents on ProcessId | where RemoteIP == 'malicious IP' | project DeviceName, ProcessFileName, Timestamp
D.IdentityLogonEvents | where IPAddress == 'malicious IP' | project DeviceName, Timestamp
AnswerA

This is the correct query because DeviceNetworkEvents is the Microsoft 365 Defender table that logs outbound network connections, and it natively includes the InitiatingProcessFileName field. Filtering on RemoteIP and a 7-day Timestamp window directly narrows to the relevant events, then projecting the three required columns gives the answer without any additional joins or subqueries.

Why this answer

DeviceNetworkEvents contains network connection data including the remote IP and the initiating process details. Filtering by RemoteIP and Timestamp directly retrieves the required information without unnecessary joins or subqueries, making it the most efficient query for identifying the process that initiated the connection to a known malicious C2 server.

Exam trap

The trap here is that candidates may choose Option C thinking a join is necessary to get process details, but DeviceNetworkEvents already includes the initiating process name, making the join redundant and inefficient.

How to eliminate wrong answers

Option B is wrong because it uses a subquery on DeviceNetworkEvents to get ProcessIds, but DeviceProcessEvents does not contain network connection data; it focuses on process creation events, so it cannot directly identify processes that initiated network connections. Option C is wrong because it performs a join on ProcessId after filtering by Timestamp, which is inefficient and may return incorrect results if ProcessId is not unique across tables; it also filters RemoteIP after the join, processing more data than necessary. Option D is wrong because IdentityLogonEvents tracks authentication events, not network connections, and IPAddress in this table refers to the logon source IP, not the destination IP of a C2 server.

188
Multi-Selectmedium

A security administrator needs to block unsanctioned cloud apps in real time using a reverse proxy. Which two Microsoft Defender for Cloud Apps components must be configured?

Select 2 answers
A.Cloud Discovery
B.Conditional Access App Control
C.App governance
D.Session control policies
AnswersB, D

Conditional Access App Control is the reverse proxy component of Microsoft Defender for Cloud Apps that, when integrated with Azure AD Conditional Access, intercepts user sessions to cloud apps in real time. It enables granular controls such as blocking access entirely, preventing downloads, or masking sensitive data, making it the correct infrastructure for real-time blocking of unsanctioned cloud apps.

Why this answer

Conditional Access App Control (B) is the reverse proxy component in Microsoft Defender for Cloud Apps that enforces real-time session-level monitoring and control of cloud app access. Session control policies (D) are the specific policy objects that define the actions (e.g., block download, block access) applied through that reverse proxy. Together, they enable blocking unsanctioned cloud apps in real time by intercepting user traffic via the reverse proxy architecture.

Exam trap

The trap here is that candidates confuse Cloud Discovery (which only detects unsanctioned apps via log analysis) with the real-time blocking capability, or they assume App governance provides reverse proxy controls when it actually focuses on OAuth app permissions and lifecycle management.

189
Multi-Selectmedium

Your organization uses Microsoft Defender XDR. You need to configure automatic response actions for a high-severity incident. Which TWO options are available in the Microsoft Defender XDR automated investigation and response capabilities?

Select 2 answers
A.Create a mailbox rule to delete suspicious emails
B.Isolate a device from the network
C.Collect an investigation package from a device
D.Delegate mailbox permissions
E.Reset user passwords
AnswersB, C

Isolating a device from the network is a containment action Microsoft Defender XDR can execute automatically during automated investigation and response. It satisfies the stem's requirement for an available automatic response action, restricting lateral movement without deleting the device.

Why this answer

Option B (Isolate a device from the network) is correct because Microsoft Defender XDR automated investigation and response (AIR) can automatically contain a compromised endpoint by isolating it from the network, blocking most network traffic while preserving the Defender for Endpoint connection for remediation. Option C (Collect an investigation package from a device) is correct because AIR can automatically gather forensic data from an endpoint into an investigation package, which includes running processes, network connections, scheduled tasks, and other artifacts for analyst review. Option A (Create a mailbox rule to delete suspicious emails) is not an AIR response action; mailbox-level remediation in Defender XDR is performed through actions like soft delete, hard delete, or moving messages to Junk/Deleted Items, not by creating custom mailbox rules.

Option D (Delegate mailbox permissions) is an Exchange administrative task unrelated to automated incident response. Option E (Reset user passwords) is not an automated response action provided by Defender XDR AIR; password resets are handled through identity management tools such as Microsoft Entra ID, not as a Defender XDR automated remediation.

Exam trap

MS-102 often tests the specific automated response actions available in Defender XDR, and candidates may incorrectly assume that identity-related actions like password resets are included.

190
MCQmedium

You are a security administrator. You need to configure a policy that automatically blocks sign-ins from anonymous IP addresses for all users in your Microsoft 365 tenant. Which policy should you configure in Microsoft Entra ID?

A.Password protection policy
B.Conditional Access policy with user risk condition
C.Conditional Access policy with sign-in risk condition
D.Identity Protection user risk policy
AnswerC

A Conditional Access policy with the sign-in risk condition evaluates Microsoft Entra ID Protection signals and blocks sign-ins assessed as risky, including anonymous IP usage. Applying it to all users satisfies the requirement to automatically block anonymous-IP sign-ins tenant-wide.

Why this answer

Anonymous IP address sign-ins are a sign-in risk detection in Microsoft Entra ID Protection. To automatically block them for all users, you configure a Conditional Access policy that targets All users and uses the sign-in risk condition set to High (or the specific 'Anonymous IP address' risk), with the access control set to Block. Sign-in risk evaluates the authentication attempt itself, which is exactly what anonymous IP represents.

Exam trap

MS-102 often tests the distinction between sign-in risk (real-time authentication signals like anonymous IP) and user risk (compromised credential indicators), causing candidates to pick the wrong condition.

How to eliminate wrong answers

Option A is wrong because password protection policies enforce banned password lists and lockout, not sign-in risk blocking. Option B is wrong because user risk condition targets compromised credentials (leaked credentials) rather than the anonymous IP sign-in signal. Option D is wrong because Identity Protection user risk policies remediate compromised accounts via password change, not anonymous IP blocking, and sign-in risk is enforced through Conditional Access.

191
MCQeasy

Your organization uses Microsoft Defender XDR. You need to configure automated investigation and response (AIR) for email and collaboration content. Which policy type should you configure in the Microsoft 365 Defender portal?

A.Attack simulation training
B.Safe attachments policies
C.Quarantine policies
D.Automated investigation and response
AnswerD

Automated investigation and response (AIR) is the correct policy type in the Microsoft 365 Defender portal for configuring automated response actions for email and collaboration content. It lets administrators define which automatic actions are performed (e.g., deleting malicious email, blocking malicious URLs, or disabling compromised user accounts) and whether they should run automatically or require approval. AIR leverages predefined playbooks and machine learning to analyze alerts, correlate signals across workloads, and drive remediation, making it the appropriate setting for enabling automated investigation and response.

Why this answer

Automated investigation and response (AIR) for email and collaboration content is configured via the 'Automated investigation and response' policy within the Email & collaboration section of the Microsoft 365 Defender portal. This policy allows you to set up automatic remediation actions for threats in email and collaboration tools. Option A is incorrect because Attack simulation training is used for conducting phishing simulations, not for AIR.

Option B is incorrect because Safe attachments policies protect against malicious attachments in email and are part of anti-malware settings. Option C is incorrect because Quarantine policies manage how quarantined messages are handled, not automated investigation and response.

192
MCQhard

Your organization has Microsoft Defender for Cloud Apps (MCAS) deployed. You need to create a policy that automatically blocks downloads of files classified as 'Highly Confidential' from SharePoint Online to unmanaged devices. Which policy type should you use?

A.Access policy
B.Activity policy
C.App discovery policy
D.Session policy
AnswerD

Session policies in Microsoft Defender for Cloud Apps apply real-time controls during user sessions, including blocking downloads to unmanaged devices. This matches the requirement to prevent file downloads from SharePoint Online based on the Highly Confidential classification.

Why this answer

A session policy in Microsoft Defender for Cloud Apps (MCAS) is the correct choice because it enables real-time monitoring and control of user activities in cloud apps, such as blocking downloads based on file sensitivity labels. This policy type uses reverse proxy architecture to inspect and intervene in user sessions, allowing you to block downloads of 'Highly Confidential' files from SharePoint Online to unmanaged devices.

Exam trap

The trap here is that candidates often confuse Access policies (which control who can access the app) with Session policies (which control what users can do within the app), leading them to incorrectly choose Option A when the question specifically requires blocking a file download action.

How to eliminate wrong answers

Option A is wrong because an Access policy controls access based on user, device, or location conditions (e.g., requiring multi-factor authentication) but does not inspect or block specific file downloads in real time. Option B is wrong because an Activity policy triggers alerts or automated actions based on logged activities (e.g., mass download detection) but cannot proactively block a download during the session. Option C is wrong because an App discovery policy is used to identify shadow IT and unsanctioned cloud apps, not to control file downloads within a sanctioned app like SharePoint Online.

193
Drag & Dropmedium

Drag and drop the steps to configure a compliance retention policy in Microsoft Purview in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Retention policies are created in Purview, locations selected, retention settings defined, and then published.

194
MCQmedium

Your organization uses Microsoft Defender for Identity. You receive an alert about a suspicious Kerberos ticket request. You need to investigate which user account is potentially compromised. Which tool should you use to correlate the alert with user activity?

A.Microsoft Defender XDR portal
B.Microsoft Intune admin center
C.Microsoft Purview compliance portal
D.Microsoft Entra admin center
AnswerA

The Microsoft Defender XDR portal (security.microsoft.com) is the correct console because it unifies alerts from Defender for Identity with Defender for Endpoint, Defender for Office 365, and Defender for Cloud Apps into a single incident queue and entity timeline. Identity-related alerts—such as suspicious Kerberos authentication, LAN-LAN traffic, or privilege escalation—are ingested from Defender for Identity sensors on domain controllers and correlated to show attack narratives like lateral movement. This cross-domain correlation is what makes it the central place to investigate and respond to identity threats.

Why this answer

The Microsoft Defender XDR portal (security.microsoft.com) provides a unified incident queue that correlates alerts from Defender for Identity with user activity, including Kerberos ticket requests. This allows you to investigate the specific user account involved by examining the alert timeline, related events, and entity details such as the account's authentication patterns and potential lateral movement.

Exam trap

The trap here is that candidates may confuse the Microsoft Entra admin center (which handles identity configuration) with the Microsoft Defender XDR portal (which handles security incident correlation), leading them to choose D instead of A.

How to eliminate wrong answers

Option B is wrong because the Microsoft Intune admin center focuses on device management, compliance policies, and app deployment, not on security alert correlation or user authentication activity. Option C is wrong because the Microsoft Purview compliance portal is designed for data governance, eDiscovery, and compliance management, not for investigating real-time security alerts like suspicious Kerberos ticket requests. Option D is wrong because the Microsoft Entra admin center handles identity and access management, including user settings and conditional access policies, but it does not provide the integrated incident investigation and threat correlation capabilities needed for Defender for Identity alerts.

195
MCQmedium

A security administrator wants to block users from uploading files to personal cloud storage apps (e.g., Dropbox) from managed Windows devices, while allowing access from compliant mobile devices. Which Microsoft 365 Defender feature should be used?

A.Microsoft Defender for Endpoint Attack Surface Reduction rules
B.Microsoft Defender for Cloud Apps session policy
C.Microsoft Defender for Office 365 Safe Attachments
D.Microsoft Defender for Identity
AnswerB

Microsoft Defender for Cloud Apps session policies operate through a reverse proxy in conjunction with Azure AD Conditional Access, allowing real-time inspection of a user's SaaS app session. The policy engine can enforce granular actions such as blocking a file upload, download, or print after evaluating device compliance and file attributes. This makes it the correct mechanism to stop users from uploading files to personal cloud storage apps while still allowing compliant access elsewhere.

Why this answer

Microsoft Defender for Cloud Apps session policies use reverse proxy architecture to monitor and control user activities in real time. By configuring a session policy with the 'Block' action for the 'Upload file' activity on managed Windows devices, the administrator can prevent file uploads to personal cloud storage apps like Dropbox. Conditional Access App Control enforces this policy based on device compliance, allowing compliant mobile devices to bypass the block.

Exam trap

The trap here is that candidates confuse host-level ASR rules (Option A) with cloud-level session policies, failing to recognize that ASR rules cannot enforce conditional access based on device compliance or control uploads to specific cloud apps.

How to eliminate wrong answers

Option A is wrong because Attack Surface Reduction rules are host-level controls that block specific behaviors (e.g., Office apps creating child processes) but cannot differentiate between managed and unmanaged devices or enforce conditional access based on device compliance for cloud app uploads. Option C is wrong because Safe Attachments is a feature of Defender for Office 365 that scans email attachments for malware in a sandbox environment; it does not control user uploads to third-party cloud storage apps. Option D is wrong because Defender for Identity monitors on-premises Active Directory for identity-based threats (e.g., Kerberoasting, pass-the-hash) and has no capability to block file uploads to cloud apps.

196
MCQhard

A security administrator notices that users are receiving phishing emails that evade built-in anti-spam filters. The administrator wants to enable users to report these suspicious emails from Outlook and have them automatically trigger an investigation and block the sender. Which feature should be configured in Microsoft Defender for Office 365?

A.Attack simulation training
B.Threat Explorer
C.User reported settings in the Microsoft 365 Defender portal
D.Safe Links
AnswerC

User reported settings in the Microsoft 365 Defender portal, found under Settings > Email & collaboration, are the native control plane that connects end-user report actions to backend automation. An admin can route reported messages to Microsoft for analysis, to a custom mailbox, or directly into automated investigation and response, and can enable the automatically block sender rule so that confirmed phishing verdicts instantly update the tenant block list. This is precisely the kind of correlated, report-initiated blocking that the other options lack, making it the correct choice for this scenario.

Why this answer

User reported settings in the Microsoft 365 Defender portal allow administrators to configure how user-reported messages are handled. When enabled, users can report suspicious emails directly from Outlook, and these reports can automatically trigger an investigation and block the sender via automated investigation and response (AIR) policies. This directly addresses the requirement to have user-reported emails initiate security actions.

Exam trap

The trap here is that candidates often confuse user reporting features with attack simulation training or threat hunting tools, not realizing that the specific setting to enable automated investigation and blocking from user reports is found in the User reported settings within the Microsoft 365 Defender portal.

How to eliminate wrong answers

Option A is wrong because Attack simulation training is a tool for creating and launching simulated phishing campaigns to train users, not for handling real user-reported emails or triggering automated investigations. Option B is wrong because Threat Explorer is a real-time reporting and investigation tool for analyzing threats, but it does not provide a mechanism for users to report emails or automatically block senders based on user reports. Option D is wrong because Safe Links is a time-of-click protection feature that scans URLs in emails and Office documents, but it does not enable user reporting or automated investigation workflows.

197
Multi-Selecthard

A security administrator needs to discover which cloud apps are being used in the organization and then block usage of unsanctioned apps in real time using a reverse proxy. Which two Microsoft Defender for Cloud Apps features must be configured to meet these requirements? (Select all that apply.)

Select 2 answers
A.Cloud Discovery
B.App Connectors
C.Conditional Access App Control
D.API connectors
AnswersA, C

Cloud Discovery is the Defender for Cloud Apps feature that analyzes traffic logs from enterprise proxies or Microsoft Defender for Endpoint to identify brand-specific cloud app usage across the organization. It continuously monitors shadow IT by discovering applications that users access, then scores them for risk (e.g., security, compliance) to create a catalog of sanctioned and unsanctioned apps. This is the correct first step for understanding 'which cloud apps are being used' — it provides the raw visibility that later enables blocking.

Why this answer

Cloud Discovery (A) is correct because it analyzes traffic logs from your network to identify all cloud apps in use, providing visibility into sanctioned and unsanctioned apps. Conditional Access App Control (C) is correct because it enforces real-time access controls via a reverse proxy, allowing you to block unsanctioned apps as users attempt to access them.

Exam trap

The trap here is confusing App Connectors/API connectors (which provide API-based control for specific apps) with the reverse proxy and discovery capabilities of Cloud Discovery and Conditional Access App Control, leading candidates to select options that manage existing apps rather than discover and block unsanctioned ones.

← PreviousPage 3 of 3 · 197 questions total

Ready to test yourself?

Try a timed practice session using only Defender Xdr Security questions.