Courseiva

MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR

You are a Microsoft 365 administrator for Tailspin Toys. You have Microsoft Defender XDR configured with Microsoft Defender for Office 365 and Microsoft Defender for Endpoint. You need to ensure that when a user clicks a malicious link in an email, the alert is enriched with the device information of the user's computer, and the device is automatically investigated. What should you do?

⚠ Common exam trap

The trap here is believing that custom detection rules or device groups can achieve cross-service alert enrichment, when it is actually a built-in integration feature.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Ensure that the 'Microsoft Defender for Endpoint' integration is enabled in Microsoft Defender XDR and that the device is onboarded.

Microsoft Defender XDR natively integrates alerts from Defender for Office 365 and Defender for Endpoint. When a user clicks a malicious link, the alert in Defender for Office 365 can be correlated with the device if the device is onboarded to Defender for Endpoint and the services are integrated. This correlation enriches the alert with device details and can automatically initiate an investigation. Thus, ensuring the integration is enabled and devices are onboarded is the correct action.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    In Microsoft Defender for Endpoint, create a device group that includes all user devices and set the automation level to 'Full - remediate threats automatically'.

    Why it's wrong here

    Configuring a device group with full automation affects how Defender for Endpoint handles its own alerts, but it does not link email click alerts from Defender for Office 365 to devices or trigger an investigation for those alerts. The integration between services is required for cross-domain correlation.

  • ✗

    In Microsoft Defender for Office 365, configure the 'Alert correlation' setting to include device information from Defender for Endpoint.

    Why it's wrong here

    There is no 'Alert correlation' setting in Microsoft Defender for Office 365 that adds device information. Alert correlation is a feature of Microsoft Defender XDR that automatically links alerts, but it is enabled by default and does not require manual configuration. This option misstates the available configuration.

  • ✓

    Ensure that the 'Microsoft Defender for Endpoint' integration is enabled in Microsoft Defender XDR and that the device is onboarded.

    Why this is correct

    Microsoft Defender XDR automatically correlates alerts from Defender for Office 365 with device information from Defender for Endpoint when both services are integrated and the device is onboarded. This correlation enriches the alert and can trigger an automated investigation. Enabling the integration and onboarding devices is the correct approach.

  • ✗

    Enable 'Advanced hunting' in Microsoft Defender XDR and create a custom detection rule that correlates email events with device events.

    Why it's wrong here

    Advanced hunting allows you to query data across services, but creating a custom detection rule would only generate alerts; it would not automatically enrich alerts with device information or trigger an investigation. The requirement is for automatic enrichment and investigation, which is handled by built-in integration, not custom rules.

Go deeper

Related to this question

About these practice questions

Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.