Courseiva

MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR

You are a security administrator. You need to investigate a suspicious logon from an anonymous IP address. Which Microsoft Defender XDR data source should you query first?

⚠ Common exam trap

The trap is confusing identity events with cloud app events; logon attempts are identity events, while cloud app events are actions within apps after authentication.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Identity and authentication events

A suspicious logon from an anonymous IP address is an identity and authentication event. Microsoft Defender XDR's Identity and authentication events data source includes sign-in logs, authentication attempts, and related identity activities. Querying this source first will provide details such as the user account, IP address, location, and success/failure status, which are crucial for investigating the logon.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Identity and authentication events

    Why this is correct

    Identity and authentication events in Microsoft Defender XDR surface sign-in logs, including source IP, user agent and risk detections. Querying these first reveals whether the anonymous IP authenticated successfully and which account was targeted, directly addressing the suspicious logon scenario.

  • ✗

    Cloud app events

    Why it's wrong here

    Cloud app events records user and admin activity in connected cloud applications, not raw network logons from anonymous IP addresses. It is tempting because sign-in anomalies often surface there, and would be correct if the investigation concerned suspicious activity within a sanctioned SaaS application rather than the initial authentication.

  • ✗

    Endpoint device events

    Why it's wrong here

    Endpoint device events cover process, file and registry activity on devices, so they hold no sign-in telemetry for an anonymous IP address. It is tempting because compromised endpoints often precede suspicious logons, and it would be the right source when investigating malicious process execution or lateral movement on a host.

  • ✗

    Vulnerability and compliance events

    Why it's wrong here

    Vulnerability and compliance events record missing patches, misconfigurations and compliance state, not authentication activity, so they cannot show a logon from an anonymous IP. It is tempting because it is a Defender XDR data source, and it would be correct when assessing exposure or regulatory posture rather than tracing sign-in attempts.

  • ✗

    Email & collaboration events

    Why it's wrong here

    Email and collaboration events capture message traces, phishing and file sharing activity, not authentication records, so an anonymous-IP logon leaves no trace there. It is tempting because suspicious sign-ins often accompany phishing, and it would be correct when investigating a compromised mailbox or malicious email delivery.

Go deeper

Related to this question

About these practice questions

One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.