Courseiva

MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR

You are a security administrator for a company that uses Microsoft Defender XDR. A security incident involving a compromised user account has been escalated. You need to identify all devices where the compromised user account signed in within the last 7 days. Which Microsoft Defender XDR feature should you use?

⚠ Common exam trap

The trap here is assuming that incident queue or device inventory can provide a complete list of sign-in events, but they lack the granular logon data needed for this investigation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Advanced hunting with the IdentityLogonEvents table

Advanced hunting with the IdentityLogonEvents table provides a comprehensive view of sign-in events across devices, including those from Defender for Identity. By querying this table for the compromised user and a 7-day timeframe, you can accurately list all devices where the account signed in, enabling effective incident response.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Incident queue filtered by the user's email address

    Why it's wrong here

    The incident queue lists incidents, not individual sign-in events. Filtering by the user's email might show related incidents, but it does not provide a comprehensive list of devices where the user signed in. This approach is inefficient and may miss sign-ins that did not generate an incident.

  • ✗

    Device inventory filtered by the user's primary email

    Why it's wrong here

    Device inventory lists devices but does not associate them with user sign-in events. Filtering by email may show devices primarily used by that user, but it will not reveal all devices where the account signed in during a specific period, especially if the user signed in to shared or temporary devices.

  • ✓

    Advanced hunting with the IdentityLogonEvents table

    Why this is correct

    The IdentityLogonEvents table in advanced hunting contains sign-in events from Microsoft Defender for Identity, providing details such as the user account, device name, and timestamp. Querying this table for the compromised user over the last 7 days will list all devices where that account signed in, directly answering the requirement.

  • ✗

    Microsoft Defender for Cloud Apps activity log

    Why it's wrong here

    The Defender for Cloud Apps activity log focuses on cloud app access and file activities, not device sign-in events. While it may show some user activities, it does not track device-level sign-ins across the organization, making it unsuitable for identifying all devices used by the compromised account.

Go deeper

Related to this question

About these practice questions

One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.