Courseiva

MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR

You are a security administrator for a company that uses Microsoft Defender XDR. You need to create a custom detection rule that triggers when a process named 'mimikatz.exe' is executed on any device. The rule should run every hour and generate an alert. Which of the following should you use to create this rule?

⚠ Common exam trap

Many candidates confuse the incident queue with a rule creation interface, when actually incident queue is only for viewing and managing existing alerts.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Defender for Endpoint advanced hunting with a custom detection rule

Custom detection rules in Microsoft Defender for Endpoint allow security teams to create scheduled KQL queries that run against advanced hunting data and generate alerts when specific conditions are met. This is the appropriate tool for detecting process execution like mimikatz.exe on endpoints, as it provides the necessary data and scheduling capabilities.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Microsoft Defender for Office 365 threat explorer

    Why it's wrong here

    Threat explorer in Microsoft Defender for Office 365 is used to investigate email-based threats, such as phishing and malware attachments. It does not provide endpoint process execution data or the ability to create scheduled detection rules for process creation events, so it cannot detect mimikatz.exe execution on devices.

  • ✗

    Microsoft 365 Defender incident queue

    Why it's wrong here

    The incident queue in Microsoft 365 Defender displays aggregated alerts and incidents but does not provide a way to create custom detection rules. It is a monitoring and triage interface, not a rule creation tool, so it cannot be used to schedule a query for mimikatz.exe execution.

  • ✗

    Microsoft Defender for Cloud Apps activity log

    Why it's wrong here

    Microsoft Defender for Cloud Apps activity log focuses on cloud app usage and user activities, such as file downloads and logins. It does not monitor endpoint process execution, so it cannot be used to detect mimikatz.exe running on a device, nor does it support custom detection rules for such events.

  • ✓

    Microsoft Defender for Endpoint advanced hunting with a custom detection rule

    Why this is correct

    Advanced hunting in Microsoft Defender for Endpoint allows you to write KQL queries against raw event data, and custom detection rules can be created from these queries to run on a schedule, such as hourly, and generate alerts when conditions are met. This is the correct method to detect process execution like mimikatz.exe.

Go deeper

Related to this question

About these practice questions

One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.