MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
You are configuring Microsoft Defender for Identity. Which THREE capabilities does it provide?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Detection of compromised accounts through behavioral analytics.
Options B, C, and E are correct because Microsoft Defender for Identity provides detection of compromised accounts through behavioral analytics (B), detection of reconnaissance activities such as LDAP enumeration (C), and detection of lateral movement between domain-joined machines (E). Option A is incorrect because scanning email attachments for malware is a feature of Microsoft Defender for Office 365, not Defender for Identity. Option D is incorrect because creation of data loss prevention (DLP) policies is a feature of Microsoft Purview, not Defender for Identity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Scanning of email attachments for malware.
Why it's wrong here
Scanning email attachments for malware is a content-inspection task performed by Microsoft Defender for Office 365, which detonates attachments in a sandbox and checks reputation and patterns. Defender for Identity does not inspect message content; it consumes network traffic and Windows events from domain controllers to focus solely on identity-based attack detection. Therefore this is not a Defender for Identity capability.
- ✓
Detection of compromised accounts through behavioral analytics.
Why this is correct
Detection of compromised accounts through behavioral analytics is a core Defender for Identity feature. It establishes baselines for users and machines, then uses machine learning to flag anomalies such as impossible travel, unusual logon hours, or abnormal service usage. Once an account's behavior deviates from its profile, the sensor raises an alert, enabling investigation and remediation of the compromise.
- ✓
Detection of reconnaissance activities such as LDAP enumeration.
Why this is correct
Defender for Identity detects reconnaissance by parsing LDAP queries sent to domain controllers and matching them against known enumeration patterns. Attackers often use LDAP to query directory attributes such as group memberships, ACLs, or service principal names, so the sensor flags suspicious query bursts or anomalous attribute retrieval. This is a distinct detection category focused on the discovery phase before lateral movement or privilege escalation.
- ✗
Creation of data loss prevention (DLP) policies.
Why it's wrong here
Data loss prevention (DLP) policies are authored and enforced in Microsoft Purview (formerly the compliance center), where you define rules for sensitive content across email, SharePoint, OneDrive, and endpoints. Defender for Identity has no policy creation interface and does not inspect content; it generates security alerts based on identity behavior and authentication events. Thus, creating DLP policies is outside its scope and is incorrect for this question.
- ✓
Detection of lateral movement between domain-joined machines.
Why this is correct
Lateral movement detection is a signature capability of Defender for Identity, which analyzes authentication and network traffic between domain-joined hosts. It identifies techniques such as Pass-the-Hash, Pass-the-Ticket, and remote service creation (SMB/WMI/PsExec) that attackers use to pivot. By correlating these events with the originating account and machine, the sensor provides a detailed attack path and alerts on suspicious movement across the enterprise.
Go deeper
Related to this question
Learn chapter
Microsoft 365 Usage Analytics and Reports
Key term
Office 365
Office 365 is a cloud-based subscription service from Microsoft that provides access to productivity applications like Word, Excel, and Outlook, along with other cloud services, for a monthly or annual fee.
Key term
Defender for Office 365
Microsoft Defender for Office 365 is a cloud-based email security service that protects organizations against advanced threats like phishing, malware, and business email compromise by scanning emails, attachments, and links in real time.
About these practice questions
Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.