Courseiva

MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR

You are a security administrator for a large enterprise with 10,000 users. The company uses Microsoft 365 E5 licenses, which include Microsoft Defender XDR. The company has recently experienced a series of ransomware attacks where attackers gained initial access through phishing emails, then moved laterally using compromised credentials, and finally deployed ransomware on file servers. The CISO wants to implement a comprehensive defense strategy that reduces the attack surface and automates response. The requirements are: 1) Prevent phishing emails from reaching users, especially those targeting executives. 2) Detect and block lateral movement using compromised credentials. 3) Automatically contain compromised devices during an incident. 4) Provide a unified incident view across email, endpoints, and identities. You need to recommend a solution that meets all requirements with minimal manual effort. What should you do?

⚠ Common exam trap

MS-102 often tests the misconception that Microsoft Sentinel or Purview alone can provide comprehensive XDR capabilities, when in fact Defender XDR is the integrated solution that natively meets prevention, detection, and automated response requirements with minimal manual effort.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure Microsoft Defender XDR by enabling Defender for Office 365 with anti-phish and impersonation protection, Defender for Identity, and Defender for Endpoint with automated investigation and response.

It leverages the native Microsoft Defender XDR suite, which directly addresses all four requirements: Defender for Office 365 with anti-phish and impersonation protection prevents phishing emails (requirement 1); Defender for Identity detects lateral movement using compromised credentials by monitoring on-premises Active Directory signals (requirement 2); Defender for Endpoint with automated investigation and response automatically contains compromised devices (requirement 3); and the integrated Defender XDR portal provides a unified incident view across email, endpoints, and identities (requirement 4). This solution requires minimal manual effort because the components are natively integrated and automation is built-in.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Configure Microsoft Defender XDR by enabling Defender for Office 365 with anti-phish and impersonation protection, Defender for Identity, and Defender for Endpoint with automated investigation and response.

    Why this is correct

    This is the correct approach because Microsoft Defender XDR unifies email, identity, and endpoint signals into a single incident pipeline. Defender for Office 365's anti-phishing and impersonation protection blocks malicious messages at the transport layer, Defender for Identity detects Kerberoasting, pass-the-hash, and other lateral movement techniques using Active Directory signals, and Defender for Endpoint's automated investigation and response can isolate endpoints and remediate ransomware artifacts. Correlating these alerts in the XDR incident view lets you see the full attack chain and contain it before broad encryption occurs.

  • ✗

    Use Microsoft Purview to classify and protect sensitive data, and configure data loss prevention policies to block ransomware.

    Why it's wrong here

    Microsoft Purview is a data governance and compliance platform, not an attack-detection or response control. Data loss prevention policies are designed to stop sensitive data from leaving the tenant—they cannot recognize malicious email payloads, detect credential theft followed by lateral movement, or quarantine a compromised endpoint. Labeling and classifying files may reduce the blast radius of data exfiltration, but it provides no active defense against ransomware execution or automatic device containment, so it fails the stated requirements.

  • ✗

    Deploy Microsoft Sentinel and create analytics rules to detect phishing, lateral movement, and ransomware. Configure automated playbooks to contain devices.

    Why it's wrong here

    Microsoft Sentinel is a cloud-native SIEM/SOAR that can ingest logs and trigger playbooks, but as a stand-alone deployment it lacks native email-prevention controls and endpoint containment actions. You would need to connect Microsoft Defender XDR (or third-party tools) to supply the phishing telemetry, identity signals, and automated isolation duties; without those integrations, Sentinel only raises alerts after the fact. Custom analytics rules and playbooks can orchestrate a response, but they cannot stop an impersonation attack before delivery or prevent an attacker from moving laterally in the meantime.

  • ✗

    Upgrade to Microsoft Entra ID P2 and enable Identity Protection for risky sign-ins and user risk. Use Conditional Access to block access from compromised devices.

    Why it's wrong here

    Entra ID P2 and Identity Protection address identity risk by flagging suspicious sign-ins, requiring MFA, and applying Conditional Access policies, but they operate only at the authentication layer. A compromised device or a delivered phishing email is outside the scope of Identity Protection, so an attacker who has already stolen credentials can still move laterally from a domain-joined machine. Conditional Access can challenge or block risky sessions, yet it cannot quarantine the endpoint, scan email attachments, or remediate ransomware files already executed—leaving critical parts of the attack chain unmanaged.

Go deeper

Related to this question

About these practice questions

This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.