MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
Exhibit
Refer to the exhibit.
```json
{
"displayName": "Custom Detection - Lateral Movement via SMB",
"queryText": "DeviceNetworkEvents | where RemotePort == 445 and ActionType == 'ConnectionSuccess' | join kind=inner (DeviceProcessEvents | where FileName == 'powershell.exe') on DeviceId | project Timestamp, DeviceName, AccountName, RemoteIP"
}
```You create a custom detection rule in Microsoft Defender XDR using the KQL query shown in the exhibit. The rule is intended to detect lateral movement via SMB. After deploying the rule, you notice that it generates many false positives from legitimate administrative activity. What is the most effective way to reduce false positives?
⚠ Common exam trap
MS-102 often tests tuning of detection rules, and candidates may think that simply removing joins or changing time windows will reduce false positives. The trap is to overlook that targeted exclusions based on administrative context are the most effective and precise method.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add a filter to exclude specific administrative accounts or IP ranges
Adding a filter to exclude specific administrative accounts or IP ranges is the most effective way to reduce false positives from legitimate administrative activity. Since the rule detects lateral movement via SMB, legitimate admins may perform similar actions. By excluding known admin accounts or trusted IP ranges, you can suppress alerts for benign activity while still detecting malicious lateral movement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Filter for only inbound SMB connections
Why it's wrong here
Filtering for only inbound SMB connections would miss lateral movement because attackers on a compromised host initiate outbound connections to remote targets. Inbound SMB traffic is often normal file sharing or other benign server activity, making that filter both blind to the attack direction and noisy with false positives. Lateral movement detection should look for processes that initiate outbound network connections.
- ✗
Remove the join with DeviceProcessEvents
Why it's wrong here
Removing the join with DeviceProcessEvents would strip the query of its ability to associate a network connection with the specific parent process that initiated it. Without this correlation, you are left with raw DeviceNetworkEvents that show SMB connections but no context about whether a legitimate service, user, or attacker tool created them. The join is essential for mapping the observed connection to a process like powershell.exe or wmic.exe, which is the core heuristic for flagging suspicious lateral movement.
- ✓
Add a filter to exclude specific administrative accounts or IP ranges
Why this is correct
Adding a filter to exclude specific administrative accounts or IP ranges is a targeted false-positive reduction technique that preserves the detection logic while eliminating known, legitimate activity. For example, a SecOps team might suppress alerts from their jump-box IPs or privileged service accounts that routinely perform SMB admin tasks, so the rule only fires on anomalies. However, exclusions must be kept narrow and periodically reviewed, or attackers could abuse a broad allowlist to evade detection.
- ✗
Increase the time window of the query
Why it's wrong here
Increasing the time window of the query would cause the detection to inspect a longer historical range of SMB activity, which almost always increases false positives because more benign administrative or backup traffic will be included in the analysis. It also adds significant query performance overhead and can slow down alert generation in a high-volume environment. The real issue is not that the rule misses enough events, but that it includes too much noise, so the solution is to filter rather than broaden the search.
Go deeper
Related to this question
Learn chapter
Sensitivity Labels: Admin Configuration
Key term
XDR
XDR, or Extended Detection and Response, is a unified security platform that collects and correlates data across multiple security layers—endpoints, networks, servers, cloud workloads, and email—to improve threat detection and enable faster response.
Key term
Microsoft Defender XDR
Microsoft Defender XDR is a unified security platform that automatically correlates alerts from across an organization's endpoints, email, identities, and cloud apps to stop complex attacks.
About these practice questions
One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.