Courseiva

MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR

You are configuring Microsoft Defender for Identity. Which THREE capabilities does it provide?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Detection of compromised accounts through behavioral analytics.

Options B, C, and E are correct because Microsoft Defender for Identity provides detection of compromised accounts through behavioral analytics (B), detection of reconnaissance activities such as LDAP enumeration (C), and detection of lateral movement between domain-joined machines (E). Option A is incorrect because scanning email attachments for malware is a feature of Microsoft Defender for Office 365, not Defender for Identity. Option D is incorrect because creation of data loss prevention (DLP) policies is a feature of Microsoft Purview, not Defender for Identity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Scanning of email attachments for malware.

    Why it's wrong here

    Scanning email attachments for malware is a content-inspection task performed by Microsoft Defender for Office 365, which detonates attachments in a sandbox and checks reputation and patterns. Defender for Identity does not inspect message content; it consumes network traffic and Windows events from domain controllers to focus solely on identity-based attack detection. Therefore this is not a Defender for Identity capability.

  • ✓

    Detection of compromised accounts through behavioral analytics.

    Why this is correct

    Detection of compromised accounts through behavioral analytics is a core Defender for Identity feature. It establishes baselines for users and machines, then uses machine learning to flag anomalies such as impossible travel, unusual logon hours, or abnormal service usage. Once an account's behavior deviates from its profile, the sensor raises an alert, enabling investigation and remediation of the compromise.

  • ✓

    Detection of reconnaissance activities such as LDAP enumeration.

    Why this is correct

    Defender for Identity detects reconnaissance by parsing LDAP queries sent to domain controllers and matching them against known enumeration patterns. Attackers often use LDAP to query directory attributes such as group memberships, ACLs, or service principal names, so the sensor flags suspicious query bursts or anomalous attribute retrieval. This is a distinct detection category focused on the discovery phase before lateral movement or privilege escalation.

  • ✗

    Creation of data loss prevention (DLP) policies.

    Why it's wrong here

    Data loss prevention (DLP) policies are authored and enforced in Microsoft Purview (formerly the compliance center), where you define rules for sensitive content across email, SharePoint, OneDrive, and endpoints. Defender for Identity has no policy creation interface and does not inspect content; it generates security alerts based on identity behavior and authentication events. Thus, creating DLP policies is outside its scope and is incorrect for this question.

  • ✓

    Detection of lateral movement between domain-joined machines.

    Why this is correct

    Lateral movement detection is a signature capability of Defender for Identity, which analyzes authentication and network traffic between domain-joined hosts. It identifies techniques such as Pass-the-Hash, Pass-the-Ticket, and remote service creation (SMB/WMI/PsExec) that attackers use to pivot. By correlating these events with the originating account and machine, the sensor provides a detailed attack path and alerts on suspicious movement across the enterprise.

Go deeper

Related to this question

About these practice questions

Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.