MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
You are a security administrator for a company that uses Microsoft Defender XDR. A security incident involving a compromised user account has been escalated. You need to identify all devices where the compromised user account signed in within the last 7 days. Which Microsoft Defender XDR feature should you use?
⚠ Common exam trap
The trap here is assuming that incident queue or device inventory can provide a complete list of sign-in events, but they lack the granular logon data needed for this investigation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Advanced hunting with the IdentityLogonEvents table
Advanced hunting with the IdentityLogonEvents table provides a comprehensive view of sign-in events across devices, including those from Defender for Identity. By querying this table for the compromised user and a 7-day timeframe, you can accurately list all devices where the account signed in, enabling effective incident response.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Incident queue filtered by the user's email address
Why it's wrong here
The incident queue lists incidents, not individual sign-in events. Filtering by the user's email might show related incidents, but it does not provide a comprehensive list of devices where the user signed in. This approach is inefficient and may miss sign-ins that did not generate an incident.
- ✗
Device inventory filtered by the user's primary email
Why it's wrong here
Device inventory lists devices but does not associate them with user sign-in events. Filtering by email may show devices primarily used by that user, but it will not reveal all devices where the account signed in during a specific period, especially if the user signed in to shared or temporary devices.
- ✓
Advanced hunting with the IdentityLogonEvents table
Why this is correct
The IdentityLogonEvents table in advanced hunting contains sign-in events from Microsoft Defender for Identity, providing details such as the user account, device name, and timestamp. Querying this table for the compromised user over the last 7 days will list all devices where that account signed in, directly answering the requirement.
- ✗
Microsoft Defender for Cloud Apps activity log
Why it's wrong here
The Defender for Cloud Apps activity log focuses on cloud app access and file activities, not device sign-in events. While it may show some user activities, it does not track device-level sign-ins across the organization, making it unsuitable for identifying all devices used by the compromised account.
Go deeper
Related to this question
Learn chapter
Endpoint DLP for Windows Devices
Key term
XDR
XDR, or Extended Detection and Response, is a unified security platform that collects and correlates data across multiple security layers—endpoints, networks, servers, cloud workloads, and email—to improve threat detection and enable faster response.
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
About these practice questions
One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.