Courseiva
Deploy and manage a Microsoft 365 tenantmediumMultiple ChoiceObjective-mapped

MS-102 Deploy and manage a Microsoft 365 tenant Practice Question

You are the Microsoft 365 administrator for a multinational company. The company has deployed Microsoft Defender for Office 365 and Microsoft Defender for Cloud Apps. Recently, the security team detected that a user's credentials were compromised and used to access SharePoint Online from an unusual location. You need to investigate the incident and determine the full scope of the breach. The solution must use Microsoft 365 Defender to correlate events. What should you do first?

⚠ Common exam trap

It's easy for candidates to default to the audit log (Option A) because it is familiar from compliance scenarios, but the question explicitly requires correlation across workloads using Microsoft 365 Defender, which is only possible with advanced hunting's cross-table queries.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Use advanced hunting in Microsoft 365 Defender portal to query for events related to the user across workloads.

Advanced hunting in the Microsoft 365 Defender portal allows you to query raw, cross-workload telemetry (e.g., from Identity, Exchange Online, SharePoint Online, and Defender for Cloud Apps) in a single Kusto Query Language (KQL) query. This is the most efficient first step to correlate events such as sign-ins, mailbox access, file downloads, and app sessions related to the compromised user, enabling you to determine the full scope of the breach across all Microsoft 365 services.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Use the Microsoft Purview compliance portal to search for the user's activity in audit logs.

    Why it's wrong here

    The Microsoft Purview compliance portal's audit log search is primarily a compliance tool, providing coarse-grained activities (e.g., 'User signed in') from a limited set of workloads, with a default retention period of only 90 days (or 180 for E5). It lacks KQL-based correlation across endpoints, email, and identity, so it cannot efficiently timeline a user's actions for a threat investigation. While useful for compliance audits, it is not the optimal first stop for hunting cross-workload activity.

  • Use advanced hunting in Microsoft 365 Defender portal to query for events related to the user across workloads.

    Why this is correct

    Advanced hunting in the Microsoft 365 Defender portal (now Microsoft Defender XDR) is a KQL-based, unified query interface that spans email, identity, endpoints, and cloud apps. It lets you join schema tables such as EmailEvents, IdentityLogonEvents, and CloudAppEvents to correlate a user's actions across a single incident, enabling detection of lateral movement or exfiltration. This is the correct first step because it uses the native, integrated signal of Defender XDR without additional licensing or setup.

  • Use Microsoft Defender for Cloud Apps to investigate the user's activity log.

    Why it's wrong here

    Microsoft Defender for Cloud Apps (MCAS) focuses exclusively on SaaS and cloud platform activities, such as file downloads or sign-ins from third-party apps (e.g., Dropbox, AWS). It does not cover Exchange Online mail events, Teams messages, or on-premises Active Directory sign-ins, so a user's full attack surface would be missed. Additionally, CloudAppEvents is just one schema in advanced hunting; the Defender portal provides a broader, normalized view, making a separate MCAS investigation redundant when advanced hunting is available.

  • Use Microsoft Sentinel to query the user's events from the workspace.

    Why it's wrong here

    Microsoft Sentinel is a full SIEM that can consume and analyze logs, but using it for a user investigation requires ingesting data via connectors and having a workspace provisioned with the necessary pricing tier (Pay-as-you-go or Microsoft Sentinel capacity). When a threat is suspected, the integrated, default tool in Defender XDR is advanced hunting—Sentinel is more appropriate for long-term archiving or complex, multi-source correlation that extends beyond M365 data. Querying a Sentinel workspace as a first step adds latency and licensing overhead with no immediate benefit over the built-in Defender portal query.

About these practice questions

One of 241 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.