MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
You are investigating an incident in Microsoft Defender XDR. The incident involves multiple alerts from different sources. Which THREE actions should you take during the investigation?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Review the incident timeline to understand the sequence of events.
Options A, C, and D are correct because during investigation, you should analyze alerts, gather evidence, and isolate affected devices. Option B is wrong because immediately deleting all related emails may destroy evidence. Option E is wrong because resetting passwords should be done after analysis.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Review the incident timeline to understand the sequence of events.
Why this is correct
Reviewing the incident timeline is the critical first step in an XDR investigation because it presents a chronological, correlated view of all alerts, user activities, and device events associated with the incident. This lets you reconstruct the attack chain from initial access to lateral movement and data exfiltration, identify which entities are truly affected, and establish what evidence must be preserved. Without this context, any containment or remediation action may be premature or miss the root cause.
- ✗
Delete all emails related to the incident from all mailboxes.
Why it's wrong here
Deleting emails from all mailboxes during an investigation destroys key forensic evidence, such as the original phishing payload, headers, and delivery metadata, which are often necessary to trace the attack vector and correlate with other telemetry in Defender XDR. It also breaks the chain of custody and could violate eDiscovery or legal hold obligations, potentially creating compliance or legal liability. Containment should never involve unilateral deletion of mailbox items; instead, use Teams or email holds if you need to temporarily restrict access.
- ✓
Use advanced hunting to query for related activities across devices and identities.
Why this is correct
Advanced hunting in Microsoft Defender XDR allows you to write KQL (Kusto Query Language) queries to pivot on specific indicators across data schemas like EmailEvents, IdentityLogonEvents, and DeviceProcessEvents. This correlative analysis goes beyond the preset incident timeline and lets you uncover related activities on other devices or identities that were not initially flagged as alerts. It is invaluable for mapping the full scope of the attack and for testing hypotheses about attacker behavior in your specific environment.
- ✓
Isolate affected devices from the network using Microsoft Defender for Endpoint.
Why this is correct
Isolating affected devices using Microsoft Defender for Endpoint is a proper containment move because it immediately stops the device from communicating with other assets and the internet, which limits lateral movement and disrupts command-and-control traffic while preserving the device's disk and memory for later forensic analysis. This action is reversible and can be applied selectively (for example, allowing certain Microsoft services) depending on the investigation needs. It is a standard incident-response step that prevents the attack from spreading without destroying evidence.
- ✗
Reset the passwords of all user accounts involved.
Why it's wrong here
Resetting the passwords of all user accounts involved is a remediation step that should be performed after you fully understand the scope and impact of the incident, not as an initial action. Doing this prematurely can lead to service outages, lock out legitimate users, and potentially alert the attacker that their activity is being investigated, prompting them to accelerate data destruction or secondary access. Also, if the attacker has established persistence via tokens, sessions, or other credential-harvesting mechanisms, a simple password reset will not eliminate that access and could give you a false sense of security.
Go deeper
Related to this question
Learn chapter
Microsoft 365 Tenant Setup
Key term
XDR
XDR, or Extended Detection and Response, is a unified security platform that collects and correlates data across multiple security layers—endpoints, networks, servers, cloud workloads, and email—to improve threat detection and enable faster response.
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
About these practice questions
This MS-102 question is part of Courseiva's 241-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.