Courseiva

MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR

You are investigating a potential security incident in Microsoft Defender XDR. The incident involves a user who received a phishing email and clicked a link that executed a PowerShell script. You need to perform a detailed investigation of the PowerShell script's behavior across all affected devices. Which feature should you use?

⚠ Common exam trap

MS-102 often tests the distinction between advanced hunting (proactive, cross-device querying) and live response (reactive, single-device remediation), causing candidates to confuse investigation with remediation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Advanced hunting in Microsoft Defender XDR.

Advanced hunting in Microsoft Defender XDR allows you to run KQL queries across all affected devices, enabling detailed investigation of the PowerShell script's behavior. It provides access to raw event data from multiple sources, including device process events, network connections, and file operations, which are essential for understanding script execution and impact.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Advanced hunting in Microsoft Defender XDR.

    Why this is correct

    Advanced hunting in Microsoft Defender XDR is a KQL-based query tool that gives you access to raw telemetry stored in a structured schema, including tables such as DeviceProcessEvents, DeviceNetworkEvents, and EmailAttachmentInfo. You can run a query on a suspicious script hash, process name, or command line to identify every endpoint and mailbox where that script may have appeared, enabling cross-domain threat hunting. This direct access to historical, correlated data makes it the correct choice for a cross-device investigation.

  • ✗

    The Action Center in Microsoft Defender XDR.

    Why it's wrong here

    The Action Center in Microsoft Defender XDR is a management console for pending and completed remediation tasks generated by automated investigations, allowing you to approve or reject actions such as file quarantines or device isolations. It does not provide raw event telemetry or query capabilities, so it cannot be used to trace a script's execution across an entire fleet. Therefore, it is not the appropriate place for this cross-device investigation.

  • ✗

    Live Response from Microsoft Defender for Endpoint.

    Why it's wrong here

    Live Response from Microsoft Defender for Endpoint provides a real-time, interactive remote shell to a single device, allowing you to run forensic commands, collect files, and remediate issues on that endpoint. It is fundamentally a one-at-a-time tool—you must connect to each machine individually—and it does not support querying or correlating data across multiple devices in a single operation. Consequently, it cannot efficiently investigate how a script propagated or executed across the entire environment.

  • ✗

    The device timeline in the Microsoft 365 Defender portal.

    Why it's wrong here

    The device timeline, located within the Microsoft 365 Defender portal (specifically under Microsoft Defender for Endpoint), presents a chronological, single-device view of events and alerts for one endpoint at a time. While useful for forensic review of a compromised host, it lacks the ability to aggregate and correlate process creation or script execution data across multiple devices simultaneously. This makes it unsuitable for determining the full scope of the script's impact across all affected machines.

Go deeper

Related to this question

About these practice questions

Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.