MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
You are a Microsoft 365 administrator for Contoso, Ltd. The security team uses Microsoft Defender XDR. They want to be alerted when a user's Microsoft Entra ID account is disabled but the user still has an active session on a device. You need to configure a custom detection rule that triggers on this condition. Which data source and query approach should you use?
⚠ Common exam trap
The trap here is assuming that endpoint event tables like DeviceEvents contain identity-related actions, when account disablement is actually captured in identity-focused tables such as IdentityDirectoryEvents.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use the IdentityDirectoryEvents table in Microsoft Defender XDR advanced hunting with a query that filters for 'AccountDisabled' actions and joins with DeviceLogonEvents.
The requirement is to detect a disabled Microsoft Entra ID account that still has an active device session. IdentityDirectoryEvents in Microsoft Defender XDR advanced hunting records directory changes such as account disabling, and DeviceLogonEvents tracks logon activity on devices. Joining these tables allows you to identify sessions that remain active after the account is disabled. Other tables lack either the identity event or the device session context, so they cannot satisfy the scenario.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use the IdentityDirectoryEvents table in Microsoft Defender XDR advanced hunting with a query that filters for 'AccountDisabled' actions and joins with DeviceLogonEvents.
Why this is correct
IdentityDirectoryEvents captures directory-level changes, including account disablement, from Microsoft Defender for Identity. By joining with DeviceLogonEvents, you can correlate the disabled account with active sessions on devices. This combination directly addresses the scenario's requirement to detect when a disabled user still has an active device session, making it the correct approach for the custom detection rule.
- ✗
Use the AlertInfo table and filter for alerts with a severity of 'High' and a category of 'Credential Access'.
Why it's wrong here
AlertInfo contains metadata about generated alerts, not raw events. Filtering by severity and category would only surface existing alerts, not create a new detection for the specific condition of an account being disabled while a session remains active. The scenario requires proactive detection based on event data, not alert aggregation. This approach would not reliably identify the described situation and may miss it entirely.
- ✗
Use the CloudAppEvents table and filter for 'DisableAccount' operations performed by an administrator.
Why it's wrong here
CloudAppEvents captures activities from cloud applications and services, including some administrative actions, but it does not cover Microsoft Entra ID account disablement events directly. Those are recorded in IdentityDirectoryEvents. Additionally, CloudAppEvents alone cannot correlate with device sessions. Relying on this table would fail to detect the condition because the necessary identity event data is not present there.
- ✗
Use the DeviceEvents table in Microsoft Defender for Endpoint with a query that filters for 'UserAccountDisabled' actions.
Why it's wrong here
The DeviceEvents table contains endpoint events such as process creation and network connections, but it does not include identity events like account disabling from Microsoft Entra ID. Account disable events are recorded in the IdentityLogonEvents or IdentityDirectoryEvents tables within Microsoft Defender for Identity, not in DeviceEvents. Using DeviceEvents would not return the required data and the rule would never trigger.
Go deeper
Related to this question
Learn chapter
Microsoft 365 Security Posture Improvement
Key term
Microsoft Entra ID
Microsoft Entra ID is a cloud-based identity and access management service that lets employees sign in and access resources both inside and outside of your organization.
Key term
XDR
XDR, or Extended Detection and Response, is a unified security platform that collects and correlates data across multiple security layers—endpoints, networks, servers, cloud workloads, and email—to improve threat detection and enable faster response.
About these practice questions
Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.