Courseiva

MS-102 Deploy and manage a Microsoft 365 tenant Practice Question

You manage a Microsoft 365 tenant for a company that uses Microsoft Defender for Office 365 Plan 2. The security team reports that several users clicked a link in a phishing email and entered credentials on a fake sign-in page. You must identify which users were compromised and remediate their accounts as quickly as possible. What should you do?

⚠ Common exam trap

The trap here is reaching for message trace or Threat Explorer, which show delivery and URL data but cannot reveal which recipients actually submitted credentials on the phishing page.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use the Compromised users report in Microsoft 365 Defender to identify affected users, then select the users and choose to force a password reset and revoke their sessions.

The Compromised users report in Microsoft 365 Defender uses signals from Defender for Office 365 to detect when a user enters credentials on a phishing site. Because the tenant has Plan 2, the report is available and includes the affected users. From the report, the administrator can force a password reset and revoke sessions, which are the recommended containment actions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use the Compromised users report in Microsoft 365 Defender to identify affected users, then select the users and choose to force a password reset and revoke their sessions.

    Why this is correct

    In tenants with Microsoft Defender for Office 365 Plan 2, the compromised users report surfaces users whose credentials were entered on a phishing page detected by the service. From the report, an administrator can confirm the users, then force a password reset and revoke active sessions to contain the compromise quickly.

  • ✗

    Run the Get-MessageTraceV2 cmdlet in Exchange Online PowerShell for the phishing message and disable the accounts of every recipient.

    Why it's wrong here

    Message trace data shows which mailboxes received the message but not who interacted with the phishing URL. Disabling every recipient would cause unnecessary disruption and would not target the users who actually submitted credentials. This method is both inaccurate and overly broad for the scenario.

  • ✗

    Review the Attack simulation training report for the tenant and export the list of users who failed the simulation.

    Why it's wrong here

    Attack simulation training reports cover simulations that you launch, not real phishing attacks. The users who clicked a real phishing email would not appear in that report, so this would not identify the actual compromised accounts. It also provides no automated remediation of real user accounts.

  • ✗

    Open the Threat Explorer in Microsoft 365 Defender, filter by the sender address, and manually review the message trace for each recipient.

    Why it's wrong here

    Threat Explorer shows message-level and URL-level data, but it does not record which users submitted credentials on a phishing page. A message trace only shows delivery events and cannot reveal credential compromise. This approach would not identify affected users or remediate their accounts.

About these practice questions

One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.