MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
You are a security administrator for a company that uses Microsoft Defender XDR. You need to integrate Microsoft Defender XDR with Microsoft Sentinel to create a unified incident view. You want to ensure that incidents from Defender XDR are automatically created in Sentinel. What should you do?
⚠ Common exam trap
The trap here is assuming that installing a solution or configuring settings in Defender XDR is sufficient, but the incident creation toggle is specifically in the Sentinel data connector configuration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable the Microsoft Defender XDR connector in Microsoft Sentinel and turn on incident creation
Enabling the Microsoft Defender XDR connector in Microsoft Sentinel and turning on incident creation is the correct method to ensure incidents from Defender XDR are automatically created in Sentinel. This provides a unified incident view and enables Sentinel's SOAR capabilities on Defender XDR incidents.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
In Microsoft Defender XDR settings, enable the Microsoft Sentinel integration and select the Sentinel workspace
Why it's wrong here
While there is a Microsoft Sentinel integration setting in Defender XDR, it is primarily for streaming advanced hunting events to Sentinel, not for incident creation. The incident creation is configured on the Sentinel side via the data connector. This option misrepresents the configuration location and purpose.
- ✓
Enable the Microsoft Defender XDR connector in Microsoft Sentinel and turn on incident creation
Why this is correct
To integrate Defender XDR with Sentinel and have incidents automatically created in Sentinel, you must enable the Microsoft Defender XDR data connector in Sentinel and specifically turn on the option to create incidents from Defender XDR alerts. This establishes the bi-directional synchronization and ensures incidents appear in both portals.
- ✗
Configure a custom detection rule in Defender XDR that calls the Microsoft Sentinel API
Why it's wrong here
Custom detection rules in Defender XDR cannot directly call the Microsoft Sentinel API to create incidents. While you can use Logic Apps for automation, this is not the standard method for incident synchronization. The native connector is the correct approach for seamless integration.
- ✗
Install the Microsoft Sentinel solution for Microsoft Defender XDR from the Content Hub
Why it's wrong here
The Content Hub solution provides workbooks, analytics rules, and playbooks, but it does not automatically create incidents from Defender XDR. You still need to enable the data connector and incident creation. The solution alone does not establish the incident synchronization.
Go deeper
Related to this question
Learn chapter
Microsoft Defender for Cloud Apps Administration
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
Key term
XDR
XDR, or Extended Detection and Response, is a unified security platform that collects and correlates data across multiple security layers—endpoints, networks, servers, cloud workloads, and email—to improve threat detection and enable faster response.
About these practice questions
One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.