MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
You are a security administrator for a company that uses Microsoft Defender XDR. You need to investigate an incident that involves multiple alerts across different workloads. Which feature in Microsoft Defender XDR should you use to view the full attack story and related entities?
⚠ Common exam trap
Watch out — candidates often confuse the incident queue with the incident details page; the queue only lists incidents, while the details page provides the full story.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Incident details page
The incident details page in Microsoft Defender XDR is designed to provide a comprehensive view of an incident, including all related alerts, entities, and the attack story. This allows security administrators to understand the full scope and progression of the attack.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Incident details page
Why this is correct
The incident details page in Microsoft Defender XDR aggregates all alerts, entities, and automated investigations related to an incident. It provides a visual attack story, showing the sequence of events and relationships between entities, which is exactly what you need to investigate the incident.
- ✗
Advanced hunting
Why it's wrong here
Advanced hunting is a query-based tool for proactive threat hunting and does not automatically present the full attack story of an incident. It requires writing KQL queries to explore data, so it is not the primary feature for viewing incident details and related entities.
- ✗
Threat analytics
Why it's wrong here
Threat analytics provides information about emerging threats and campaigns but does not show details of a specific incident in your environment. It is a knowledge base, not an investigation tool for incidents, so it cannot display the attack story and related entities.
- ✗
Incident queue
Why it's wrong here
The incident queue provides a list of incidents and their statuses, but it does not show the full attack story or detailed relationships between entities. To view the attack story, you need to open an incident, which is not done directly from the queue view.
Go deeper
Related to this question
Learn chapter
Defender for Endpoint Deployment via Intune
Key term
Microsoft Defender XDR
Microsoft Defender XDR is a unified security platform that automatically correlates alerts from across an organization's endpoints, email, identities, and cloud apps to stop complex attacks.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.