MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
You are a security administrator for a company that uses Microsoft Defender XDR. You need to generate a report that shows the number of incidents closed as true positive, false positive, and benign in the last 30 days. You want to use built-in features without writing custom queries. What should you do?
⚠ Common exam trap
MS-102 often tests the trap of choosing Advanced Hunting or Threat Analytics for reporting when the question specifies 'built-in features without custom queries' — the correct answer is the built-in Reports section.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
In the Microsoft Defender XDR portal, go to Reports > General > Incident summary.
The Microsoft Defender XDR portal includes a built-in Reports section under General with an Incident summary report that shows incident counts by classification (true positive, false positive, benign) over a selected period such as 30 days. This requires no custom queries and directly provides the requested metrics. Navigating to Reports > General > Incident summary is the correct built-in path.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use the Microsoft Defender for Endpoint reports section.
Why it's wrong here
Defender for Endpoint reports cover device-level detections and vulnerabilities, not incident classification counts across the XDR estate. It is tempting because it is a built-in reporting area, and it would be the correct choice when reporting endpoint-specific threat or configuration data rather than incident triage outcomes.
- ✗
Use the Device health report in Microsoft Defender XDR.
Why it's wrong here
The Device health report surfaces endpoint sensor status, antivirus signatures and onboarding coverage, not incident classification outcomes. It is tempting because it lives in the same Microsoft Defender XDR reporting area, but incident verdict counts (true positive, false positive, benign) come from the Incidents queue report, which aggregates closure classifications over the selected period.
- ✗
Navigate to Threat analytics in the Defender XDR portal.
Why it's wrong here
Threat analytics profiles active threat actors and campaigns with mitigation guidance; it does not aggregate incident closure classifications. It is tempting because it is a built-in Defender XDR portal feature, and it would be the correct choice when researching a specific threat's prevalence and recommended defences.
- ✓
In the Microsoft Defender XDR portal, go to Reports > General > Incident summary.
Why this is correct
The Incident summary report is a built-in Defender XDR report that aggregates incident classifications, including true positive, false positive and benign counts, over a selectable period such as 30 days. It satisfies the no-custom-queries constraint directly, unlike advanced hunting or custom workbooks.
Go deeper
Related to this question
Learn chapter
Attack Simulation Training in Defender
Key term
XDR
XDR, or Extended Detection and Response, is a unified security platform that collects and correlates data across multiple security layers—endpoints, networks, servers, cloud workloads, and email—to improve threat detection and enable faster response.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.