MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
Which TWO actions can you perform using Microsoft Defender XDR's Advanced Hunting? (Choose two.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create custom detection rules based on query results.
Advanced Hunting in Microsoft Defender XDR allows you to run KQL queries across data from various Defender services, so option E is correct. You can also create custom detection rules based on query results, making option C correct. Option A (deploy EDR sensors) is done via group policy or Intune, not in Advanced Hunting. Option B (configure data retention) is a tenant-level setting. Option D (manage incident status) is performed in the Incidents queue, not in Advanced Hunting.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Deploy EDR sensors to endpoints.
Why it's wrong here
EDR sensor deployment is handled through onboarding packages, Intune, or Group Policy; Advanced Hunting only queries collected telemetry. It is tempting because hunting relies on endpoint data, and sensor deployment would be correct if the question asked how to onboard devices into Defender for Endpoint rather than query them.
- ✗
Configure data retention policies for logs.
Why it's wrong here
Retention policies for logs are configured in the Microsoft 365 Defender portal settings or via policy APIs, not through Advanced Hunting KQL queries. It is tempting because hunting depends on retained telemetry, and retention configuration would be correct if the question asked where to set data governance rather than query data.
- ✓
Create custom detection rules based on query results.
Why this is correct
Advanced Hunting's Kusto Query Language results can be saved as custom detection rules, which run on a schedule and trigger alerts or automated response actions. This satisfies the stem's requirement for an action available directly within Microsoft Defender XDR, rather than relying on a separate portal or service.
- ✗
Manage the status of incidents.
Why it's wrong here
Advanced Hunting runs KQL queries over raw telemetry; incident status changes happen in the incidents queue or via the Microsoft Graph security API. It is tempting because hunting results can inform triage, and incident management would be correct if the question asked which portal actions handle alert triage rather than query authoring.
- ✓
Run KQL queries to hunt for threats across email, endpoints, identities, and apps.
Why this is correct
Advanced Hunting in Microsoft Defender XDR natively queries a unified schema spanning email, endpoints, identities and apps, so KQL threat hunting satisfies the cross-workload requirement in the stem. This single-query reach across all four pillars is what distinguishes it from per-workload tools such as Defender for Endpoint alone.
Go deeper
Related to this question
Learn chapter
Data Loss Prevention Policies
Key term
Intune
Microsoft Intune is a cloud-based service that helps organizations manage their users' devices and applications, ensuring security and compliance without needing to own or control the physical hardware.
Key term
EDR
Endpoint Detection and Response (EDR) is a cybersecurity technology that continuously monitors endpoint devices to detect, investigate, and respond to advanced threats.
About these practice questions
Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.