Courseiva

MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR

You are a security administrator for a company that uses Microsoft Defender XDR. You need to integrate Microsoft Defender XDR with Microsoft Sentinel to create a unified incident view. You want to ensure that incidents from Defender XDR are automatically created in Sentinel. What should you do?

⚠ Common exam trap

The trap here is assuming that installing a solution or configuring settings in Defender XDR is sufficient, but the incident creation toggle is specifically in the Sentinel data connector configuration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable the Microsoft Defender XDR connector in Microsoft Sentinel and turn on incident creation

Enabling the Microsoft Defender XDR connector in Microsoft Sentinel and turning on incident creation is the correct method to ensure incidents from Defender XDR are automatically created in Sentinel. This provides a unified incident view and enables Sentinel's SOAR capabilities on Defender XDR incidents.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    In Microsoft Defender XDR settings, enable the Microsoft Sentinel integration and select the Sentinel workspace

    Why it's wrong here

    While there is a Microsoft Sentinel integration setting in Defender XDR, it is primarily for streaming advanced hunting events to Sentinel, not for incident creation. The incident creation is configured on the Sentinel side via the data connector. This option misrepresents the configuration location and purpose.

  • ✓

    Enable the Microsoft Defender XDR connector in Microsoft Sentinel and turn on incident creation

    Why this is correct

    To integrate Defender XDR with Sentinel and have incidents automatically created in Sentinel, you must enable the Microsoft Defender XDR data connector in Sentinel and specifically turn on the option to create incidents from Defender XDR alerts. This establishes the bi-directional synchronization and ensures incidents appear in both portals.

  • ✗

    Configure a custom detection rule in Defender XDR that calls the Microsoft Sentinel API

    Why it's wrong here

    Custom detection rules in Defender XDR cannot directly call the Microsoft Sentinel API to create incidents. While you can use Logic Apps for automation, this is not the standard method for incident synchronization. The native connector is the correct approach for seamless integration.

  • ✗

    Install the Microsoft Sentinel solution for Microsoft Defender XDR from the Content Hub

    Why it's wrong here

    The Content Hub solution provides workbooks, analytics rules, and playbooks, but it does not automatically create incidents from Defender XDR. You still need to enable the data connector and incident creation. The solution alone does not establish the incident synchronization.

Go deeper

Related to this question

About these practice questions

One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.