Courseiva

MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR

You are a security administrator for a company that uses Microsoft Defender XDR. You need to investigate an incident that involves multiple alerts across different workloads. Which feature in Microsoft Defender XDR should you use to view the full attack story and related entities?

⚠ Common exam trap

Watch out — candidates often confuse the incident queue with the incident details page; the queue only lists incidents, while the details page provides the full story.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Incident details page

The incident details page in Microsoft Defender XDR is designed to provide a comprehensive view of an incident, including all related alerts, entities, and the attack story. This allows security administrators to understand the full scope and progression of the attack.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Incident details page

    Why this is correct

    The incident details page in Microsoft Defender XDR aggregates all alerts, entities, and automated investigations related to an incident. It provides a visual attack story, showing the sequence of events and relationships between entities, which is exactly what you need to investigate the incident.

  • ✗

    Advanced hunting

    Why it's wrong here

    Advanced hunting is a query-based tool for proactive threat hunting and does not automatically present the full attack story of an incident. It requires writing KQL queries to explore data, so it is not the primary feature for viewing incident details and related entities.

  • ✗

    Threat analytics

    Why it's wrong here

    Threat analytics provides information about emerging threats and campaigns but does not show details of a specific incident in your environment. It is a knowledge base, not an investigation tool for incidents, so it cannot display the attack story and related entities.

  • ✗

    Incident queue

    Why it's wrong here

    The incident queue provides a list of incidents and their statuses, but it does not show the full attack story or detailed relationships between entities. To view the attack story, you need to open an incident, which is not done directly from the queue view.

About these practice questions

Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.