Courseiva

MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR

You are a security administrator for a company that uses Microsoft Defender XDR. You need to generate a report that shows the number of incidents closed as true positive, false positive, and benign in the last 30 days. You want to use built-in features without writing custom queries. What should you do?

⚠ Common exam trap

MS-102 often tests the trap of choosing Advanced Hunting or Threat Analytics for reporting when the question specifies 'built-in features without custom queries' — the correct answer is the built-in Reports section.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

In the Microsoft Defender XDR portal, go to Reports > General > Incident summary.

The Microsoft Defender XDR portal includes a built-in Reports section under General with an Incident summary report that shows incident counts by classification (true positive, false positive, benign) over a selected period such as 30 days. This requires no custom queries and directly provides the requested metrics. Navigating to Reports > General > Incident summary is the correct built-in path.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use the Microsoft Defender for Endpoint reports section.

    Why it's wrong here

    Defender for Endpoint reports cover device-level detections and vulnerabilities, not incident classification counts across the XDR estate. It is tempting because it is a built-in reporting area, and it would be the correct choice when reporting endpoint-specific threat or configuration data rather than incident triage outcomes.

  • ✗

    Use the Device health report in Microsoft Defender XDR.

    Why it's wrong here

    The Device health report surfaces endpoint sensor status, antivirus signatures and onboarding coverage, not incident classification outcomes. It is tempting because it lives in the same Microsoft Defender XDR reporting area, but incident verdict counts (true positive, false positive, benign) come from the Incidents queue report, which aggregates closure classifications over the selected period.

  • ✗

    Navigate to Threat analytics in the Defender XDR portal.

    Why it's wrong here

    Threat analytics profiles active threat actors and campaigns with mitigation guidance; it does not aggregate incident closure classifications. It is tempting because it is a built-in Defender XDR portal feature, and it would be the correct choice when researching a specific threat's prevalence and recommended defences.

  • ✓

    In the Microsoft Defender XDR portal, go to Reports > General > Incident summary.

    Why this is correct

    The Incident summary report is a built-in Defender XDR report that aggregates incident classifications, including true positive, false positive and benign counts, over a selectable period such as 30 days. It satisfies the no-custom-queries constraint directly, unlike advanced hunting or custom workbooks.

About these practice questions

Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.