Courseiva

MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR

You are a security administrator for a company that uses Microsoft Defender XDR. You need to configure alert policies to notify the security team when specific activities occur. You want to receive notifications for alerts related to malicious file detection and suspicious sign-in attempts. Which two actions should you perform? (Choose two.)

⚠ Common exam trap

The trap here is thinking that enabling audit logging or creating DLP policies will generate the required alerts, when they serve different purposes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure email notifications for the alert policy.

To receive notifications for specific alerts in Microsoft Defender XDR, you must create an alert policy that includes the relevant detection sources and then configure email notifications for that policy. These two actions together ensure the security team is alerted about malicious files and suspicious sign-ins.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Set up a Microsoft Sentinel playbook.

    Why it's wrong here

    Microsoft Sentinel playbooks are used for automated response in a SIEM context and are not part of Microsoft Defender XDR's native alert notification system. While they can be integrated, they are not required to receive email notifications for alerts within Defender XDR, making this action unnecessary here.

  • ✗

    Create a data loss prevention (DLP) policy.

    Why it's wrong here

    DLP policies are designed to prevent sensitive data leakage and do not trigger alerts for malicious files or sign-in attempts. They operate on content and sharing activities, not on security threats like malware or anomalous logins, so they are irrelevant to this scenario.

  • ✓

    Configure email notifications for the alert policy.

    Why this is correct

    Configuring email notifications for the alert policy ensures that the security team is notified when the specified alerts are triggered. This step is essential to actually receive the notifications for malicious file detection and suspicious sign-in attempts, as the policy alone does not send emails.

  • ✓

    Create an alert policy in Microsoft 365 Defender with the appropriate detection sources.

    Why this is correct

    Creating an alert policy in Microsoft 365 Defender allows you to specify the conditions and sources for alerts. By including detection sources such as Microsoft Defender for Endpoint and Microsoft Defender for Identity, you can receive notifications for malicious file detection and suspicious sign-in attempts, respectively.

  • ✗

    Enable audit logging in Microsoft Purview compliance portal.

    Why it's wrong here

    Audit logging in Microsoft Purview records user and admin activities but does not generate alerts for malicious file detection or suspicious sign-ins. It is used for forensic investigations and compliance, not for real-time alert notifications, so it does not fulfill the requirement.

About these practice questions

One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.