Courseiva

MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR

You are a Microsoft 365 administrator for Contoso, Ltd. The security team uses Microsoft Defender XDR. They want to be alerted when a user's Microsoft Entra ID account is disabled but the user still has an active session on a device. You need to configure a custom detection rule that triggers on this condition. Which data source and query approach should you use?

⚠ Common exam trap

The trap here is assuming that endpoint event tables like DeviceEvents contain identity-related actions, when account disablement is actually captured in identity-focused tables such as IdentityDirectoryEvents.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use the IdentityDirectoryEvents table in Microsoft Defender XDR advanced hunting with a query that filters for 'AccountDisabled' actions and joins with DeviceLogonEvents.

The requirement is to detect a disabled Microsoft Entra ID account that still has an active device session. IdentityDirectoryEvents in Microsoft Defender XDR advanced hunting records directory changes such as account disabling, and DeviceLogonEvents tracks logon activity on devices. Joining these tables allows you to identify sessions that remain active after the account is disabled. Other tables lack either the identity event or the device session context, so they cannot satisfy the scenario.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use the IdentityDirectoryEvents table in Microsoft Defender XDR advanced hunting with a query that filters for 'AccountDisabled' actions and joins with DeviceLogonEvents.

    Why this is correct

    IdentityDirectoryEvents captures directory-level changes, including account disablement, from Microsoft Defender for Identity. By joining with DeviceLogonEvents, you can correlate the disabled account with active sessions on devices. This combination directly addresses the scenario's requirement to detect when a disabled user still has an active device session, making it the correct approach for the custom detection rule.

  • ✗

    Use the AlertInfo table and filter for alerts with a severity of 'High' and a category of 'Credential Access'.

    Why it's wrong here

    AlertInfo contains metadata about generated alerts, not raw events. Filtering by severity and category would only surface existing alerts, not create a new detection for the specific condition of an account being disabled while a session remains active. The scenario requires proactive detection based on event data, not alert aggregation. This approach would not reliably identify the described situation and may miss it entirely.

  • ✗

    Use the CloudAppEvents table and filter for 'DisableAccount' operations performed by an administrator.

    Why it's wrong here

    CloudAppEvents captures activities from cloud applications and services, including some administrative actions, but it does not cover Microsoft Entra ID account disablement events directly. Those are recorded in IdentityDirectoryEvents. Additionally, CloudAppEvents alone cannot correlate with device sessions. Relying on this table would fail to detect the condition because the necessary identity event data is not present there.

  • ✗

    Use the DeviceEvents table in Microsoft Defender for Endpoint with a query that filters for 'UserAccountDisabled' actions.

    Why it's wrong here

    The DeviceEvents table contains endpoint events such as process creation and network connections, but it does not include identity events like account disabling from Microsoft Entra ID. Account disable events are recorded in the IdentityLogonEvents or IdentityDirectoryEvents tables within Microsoft Defender for Identity, not in DeviceEvents. Using DeviceEvents would not return the required data and the rule would never trigger.

Go deeper

Related to this question

About these practice questions

Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.