Courseiva

MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR

You are investigating an alert in Microsoft Defender XDR that indicates a user clicked a malicious link in an email. You need to gather additional information to determine the scope of the attack. Which three sources should you examine?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Email entity page

To fully investigate a phishing incident, you should examine the alert timeline for related events, the email entity page for email details, and the user entity page for user actions. Device timeline may not be relevant if the user only clicked a link without further action. The incidents page provides a summary but not detailed scope.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Incidents page

    Why it's wrong here

    The Incidents page in Microsoft Defender XDR provides a consolidated, high-level view of an attack, grouping related alerts and affected assets into a single queue, which is useful for triage and reporting. However, it deliberately abstracts away the granular email forensics, such as message headers, sender authentication results, and individual attachment detonation details, that you need when validating a suspicious email alert. For a focused email investigation, you must pivot from the incident to the specific email entity page.

  • Email entity page

    Why this is correct

    The Email entity page is the definitive scoped view for email-borne alerts, exposing the full message record: internet message ID, sender and recipient addresses, subject, delivery status, and SPF/DKIM/DMARC authentication outcomes. It also presents linked URLs with click verdicts and extracted attachments with detonation results, enabling you to confirm the email's malicious intent. In Microsoft 365 Defender, this page is the canonical place to start when the alert originated from an email, because it centers the investigation on the artifact itself.

  • Alert timeline

    Why this is correct

    The Alert timeline provides a chronological, event-by-event narrative surrounding the email alert, including actions like email forwarding, mailbox login, URL clicks, and file detonation events. It is valuable because it reveals the sequence of attacker and user activity after the email arrived, helping you establish whether the threat propagated beyond the mailbox. For an email investigation, the timeline complements the email entity page by answering 'what happened next' rather than 'what is in this email.'

  • Device timeline

    Why it's wrong here

    The Device timeline is designed for endpoint-level forensics, logging process creation, file writes, registry changes, and network connections on a specific machine. If the email alert involves only a malicious link or attachment that was not executed on a managed endpoint, the device timeline will likely contain no direct evidence and can distract you from the actionable email data. It becomes relevant only after you confirm an endpoint interaction, such as a detonated payload, so it is an invalid primary destination for a pure email alert.

  • User entity page

    Why this is correct

    The User entity page aggregates identity-related signals for the affected mailbox owner, including sign-in logs, risk events, conditional access decisions, and user actions such as message reads or replies. This page is crucial for determining whether the email alert escalated into account compromise or data exfiltration, but it does not expose the email's internal headers, attachment scans, or URL detonation results. It is a valid investigative surface, yet it addresses the identity scope, not the email artifact scope, which is the core of this alert.

Go deeper

Related to this question

About these practice questions

One of 241 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.