MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
You are a security administrator for a company that uses Microsoft Defender XDR. You need to investigate a suspicious email that was reported by a user. You want to see the full email details, including headers, attachments, and URLs. Where should you look?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
In the Microsoft Defender XDR portal, search for the email message ID or subject to open the email entity page.
The email entity page in the Microsoft Defender XDR portal allows you to search by message ID or subject to view full email details including headers, attachments, and URLs. Option A is incorrect because the Threat analytics dashboard provides information about threats and attack patterns, not individual email details. Option B is incorrect because the user entity page shows user activity and alerts, not email details. Option D is incorrect because incident details provide alerts and evidence, but not the full email entity with headers and attachments.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use the Threat analytics dashboard to find the email.
Why it's wrong here
Threat analytics reports on campaigns, actor profiles and vulnerabilities affecting your estate; it holds no tenant message data, so no specific email can be located there. It is the correct destination when researching whether a published threat campaign applies to your environment.
- ✗
Go to the user entity page and view their email activity.
Why it's wrong here
The user entity page aggregates sign-in, device and mail activity, but exposes only summarised events rather than the raw message. Full headers, attachments and URLs live in Explorer's email entity view. Entity pages suit investigating a compromised account's behaviour across services.
- ✓
In the Microsoft Defender XDR portal, search for the email message ID or subject to open the email entity page.
Why this is correct
The email entity page in the Microsoft Defender XDR portal consolidates the full message, including headers, attachments and URLs, retrievable by message ID or subject. This gives the investigator the complete artefact set needed to assess the reported suspicious email.
- ✗
Open the incident related to the email and view the alert details.
Why it's wrong here
Alert details show the detection logic, affected entities and evidence summary, but not the complete message body. The email entity page in Explorer renders headers, attachments and URLs for triage. Incident alerts are the right starting point for correlating multiple related detections across workloads.
Go deeper
Related to this question
Learn chapter
Microsoft Defender XDR Overview for Admins
Key term
XDR
XDR, or Extended Detection and Response, is a unified security platform that collects and correlates data across multiple security layers—endpoints, networks, servers, cloud workloads, and email—to improve threat detection and enable faster response.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.