MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
You are a security administrator for a company that uses Microsoft Defender XDR. You need to create a custom detection rule that triggers when a process named 'mimikatz.exe' is executed on any device. The rule should run every hour and generate an alert. Which of the following should you use to create this rule?
⚠ Common exam trap
Many candidates confuse the incident queue with a rule creation interface, when actually incident queue is only for viewing and managing existing alerts.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Defender for Endpoint advanced hunting with a custom detection rule
Custom detection rules in Microsoft Defender for Endpoint allow security teams to create scheduled KQL queries that run against advanced hunting data and generate alerts when specific conditions are met. This is the appropriate tool for detecting process execution like mimikatz.exe on endpoints, as it provides the necessary data and scheduling capabilities.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Defender for Office 365 threat explorer
Why it's wrong here
Threat explorer in Microsoft Defender for Office 365 is used to investigate email-based threats, such as phishing and malware attachments. It does not provide endpoint process execution data or the ability to create scheduled detection rules for process creation events, so it cannot detect mimikatz.exe execution on devices.
- ✗
Microsoft 365 Defender incident queue
Why it's wrong here
The incident queue in Microsoft 365 Defender displays aggregated alerts and incidents but does not provide a way to create custom detection rules. It is a monitoring and triage interface, not a rule creation tool, so it cannot be used to schedule a query for mimikatz.exe execution.
- ✗
Microsoft Defender for Cloud Apps activity log
Why it's wrong here
Microsoft Defender for Cloud Apps activity log focuses on cloud app usage and user activities, such as file downloads and logins. It does not monitor endpoint process execution, so it cannot be used to detect mimikatz.exe running on a device, nor does it support custom detection rules for such events.
- ✓
Microsoft Defender for Endpoint advanced hunting with a custom detection rule
Why this is correct
Advanced hunting in Microsoft Defender for Endpoint allows you to write KQL queries against raw event data, and custom detection rules can be created from these queries to run on a schedule, such as hourly, and generate alerts when conditions are met. This is the correct method to detect process execution like mimikatz.exe.
Go deeper
Related to this question
Learn chapter
Exchange Mobile Device Policies (OWA)
Key term
Microsoft Defender XDR
Microsoft Defender XDR is a unified security platform that automatically correlates alerts from across an organization's endpoints, email, identities, and cloud apps to stop complex attacks.
Key term
XDR
XDR, or Extended Detection and Response, is a unified security platform that collects and correlates data across multiple security layers—endpoints, networks, servers, cloud workloads, and email—to improve threat detection and enable faster response.
About these practice questions
One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.