MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
You are a security administrator. You need to investigate a suspicious logon from an anonymous IP address. Which Microsoft Defender XDR data source should you query first?
⚠ Common exam trap
The trap is confusing identity events with cloud app events; logon attempts are identity events, while cloud app events are actions within apps after authentication.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Identity and authentication events
A suspicious logon from an anonymous IP address is an identity and authentication event. Microsoft Defender XDR's Identity and authentication events data source includes sign-in logs, authentication attempts, and related identity activities. Querying this source first will provide details such as the user account, IP address, location, and success/failure status, which are crucial for investigating the logon.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Identity and authentication events
Why this is correct
Identity and authentication events in Microsoft Defender XDR surface sign-in logs, including source IP, user agent and risk detections. Querying these first reveals whether the anonymous IP authenticated successfully and which account was targeted, directly addressing the suspicious logon scenario.
- ✗
Cloud app events
Why it's wrong here
Cloud app events records user and admin activity in connected cloud applications, not raw network logons from anonymous IP addresses. It is tempting because sign-in anomalies often surface there, and would be correct if the investigation concerned suspicious activity within a sanctioned SaaS application rather than the initial authentication.
- ✗
Endpoint device events
Why it's wrong here
Endpoint device events cover process, file and registry activity on devices, so they hold no sign-in telemetry for an anonymous IP address. It is tempting because compromised endpoints often precede suspicious logons, and it would be the right source when investigating malicious process execution or lateral movement on a host.
- ✗
Vulnerability and compliance events
Why it's wrong here
Vulnerability and compliance events record missing patches, misconfigurations and compliance state, not authentication activity, so they cannot show a logon from an anonymous IP. It is tempting because it is a Defender XDR data source, and it would be correct when assessing exposure or regulatory posture rather than tracing sign-in attempts.
- ✗
Email & collaboration events
Why it's wrong here
Email and collaboration events capture message traces, phishing and file sharing activity, not authentication records, so an anonymous-IP logon leaves no trace there. It is tempting because suspicious sign-ins often accompany phishing, and it would be correct when investigating a compromised mailbox or malicious email delivery.
Go deeper
Related to this question
Learn chapter
Global Administrator Best Practices
Key term
XDR
XDR, or Extended Detection and Response, is a unified security platform that collects and correlates data across multiple security layers—endpoints, networks, servers, cloud workloads, and email—to improve threat detection and enable faster response.
Key term
Microsoft Defender XDR
Microsoft Defender XDR is a unified security platform that automatically correlates alerts from across an organization's endpoints, email, identities, and cloud apps to stop complex attacks.
About these practice questions
One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.