MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
You are a security administrator for an organization that uses Microsoft Defender XDR. You want to provide your security operations team with a unified view of all incidents across endpoints, email, and identities. You also want to automate the creation of incidents when correlated alerts are detected. What should you do?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Navigate to the Microsoft Defender XDR portal (security.microsoft.com) and use the Incidents view.
The Microsoft Defender XDR portal (security.microsoft.com) provides a unified incident view and automatically correlates alerts from multiple workloads (endpoints, email, identities) into incidents. Option B is incorrect because Microsoft Defender for Endpoint portal focuses only on endpoint data, not the unified view across all services. Option C is incorrect because while Microsoft Sentinel can provide a unified view, it requires additional licensing, configuration, and does not automatically create incidents from correlated alerts without custom analytics rules. Option D is incorrect because custom KQL queries and workbooks provide visibility but do not automate incident creation; that requires built-in correlation from Microsoft Defender XDR.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Navigate to the Microsoft Defender XDR portal (security.microsoft.com) and use the Incidents view.
Why this is correct
The Incidents view in the Microsoft Defender XDR portal correlates alerts across endpoints, email and identities into unified incidents, and automatic incident creation triggers when correlated alerts fire, meeting both the visibility and automation requirements.
- ✗
Open the Microsoft Defender for Endpoint portal and create a dashboard for all alerts.
Why it's wrong here
The Defender for Endpoint portal surfaces endpoint alerts only, so email and identity signals remain siloed and no cross-workload incident automation occurs. A dashboard is a visualisation layer, not a correlation engine. This fits an endpoint-only monitoring requirement, not unified incidents spanning endpoints, email and identities.
- ✗
Install Microsoft Sentinel and configure data connectors for all workloads.
Why it's wrong here
Sentinel ingests and correlates data, but deploying it adds a separate SIEM workspace and connectors rather than using Defender XDR's native cross-workload incident correlation and automated incident creation. Sentinel is the right choice when centralised SIEM analytics, long-term retention or custom detection rules across non-Microsoft sources are needed.
- ✗
Create a custom KQL query that correlates alerts from different sources and create a workbook.
Why it's wrong here
A KQL query and workbook only display correlated data; they neither generate incidents nor trigger automated response. Defender XDR already correlates alerts across endpoints, email and identities into incidents natively. Custom queries suit bespoke hunting or reporting, not the built-in incident automation this scenario requires.
Go deeper
Related to this question
Learn chapter
Microsoft 365 Security Posture Improvement
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
Key term
Microsoft Defender XDR
Microsoft Defender XDR is a unified security platform that automatically correlates alerts from across an organization's endpoints, email, identities, and cloud apps to stop complex attacks.
About these practice questions
This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.