MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
You are a security administrator for a company that uses Microsoft Defender XDR. You need to configure alert policies to notify the security team when specific activities occur. You want to receive notifications for alerts related to malicious file detection and suspicious sign-in attempts. Which two actions should you perform? (Choose two.)
⚠ Common exam trap
The trap here is thinking that enabling audit logging or creating DLP policies will generate the required alerts, when they serve different purposes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure email notifications for the alert policy.
To receive notifications for specific alerts in Microsoft Defender XDR, you must create an alert policy that includes the relevant detection sources and then configure email notifications for that policy. These two actions together ensure the security team is alerted about malicious files and suspicious sign-ins.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Set up a Microsoft Sentinel playbook.
Why it's wrong here
Microsoft Sentinel playbooks are used for automated response in a SIEM context and are not part of Microsoft Defender XDR's native alert notification system. While they can be integrated, they are not required to receive email notifications for alerts within Defender XDR, making this action unnecessary here.
- ✗
Create a data loss prevention (DLP) policy.
Why it's wrong here
DLP policies are designed to prevent sensitive data leakage and do not trigger alerts for malicious files or sign-in attempts. They operate on content and sharing activities, not on security threats like malware or anomalous logins, so they are irrelevant to this scenario.
- ✓
Configure email notifications for the alert policy.
Why this is correct
Configuring email notifications for the alert policy ensures that the security team is notified when the specified alerts are triggered. This step is essential to actually receive the notifications for malicious file detection and suspicious sign-in attempts, as the policy alone does not send emails.
- ✓
Create an alert policy in Microsoft 365 Defender with the appropriate detection sources.
Why this is correct
Creating an alert policy in Microsoft 365 Defender allows you to specify the conditions and sources for alerts. By including detection sources such as Microsoft Defender for Endpoint and Microsoft Defender for Identity, you can receive notifications for malicious file detection and suspicious sign-in attempts, respectively.
- ✗
Enable audit logging in Microsoft Purview compliance portal.
Why it's wrong here
Audit logging in Microsoft Purview records user and admin activities but does not generate alerts for malicious file detection or suspicious sign-ins. It is used for forensic investigations and compliance, not for real-time alert notifications, so it does not fulfill the requirement.
Go deeper
Related to this question
Learn chapter
Email Quarantine and Submission Management
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.