Courseiva

MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR

Your organization is a financial services company with 5,000 users. You use Microsoft Defender XDR, including Defender for Endpoint Plan 2, Defender for Identity, Defender for Office 365 Plan 2, and Defender for Cloud Apps. You have recently deployed Microsoft Copilot for Security to assist your security operations center (SOC) analysts. A high-severity incident is generated: 'A user named jdoe accessed a malicious IP address from their device, and then logged into Azure Portal from an anonymous IP address. Defender for Identity detected a suspicious Kerberos ticket request from the same user's domain controller. The SOC analysts are overwhelmed with alerts and need to quickly understand the full scope of the incident, including related alerts, impacted assets, and recommended actions. They also want to use natural language to ask questions about the incident. What should you do to enable the analysts to efficiently investigate this incident?

⚠ Common exam trap

MS-102 often tests the misconception that Advanced Hunting or automated investigation alone can provide natural language summaries, but only Copilot for Security offers that capability.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use Microsoft Copilot for Security integrated with Microsoft Defender XDR to get a natural language summary of the incident, ask follow-up questions, and receive recommended actions.

Microsoft Copilot for Security integrated with Microsoft Defender XDR provides natural language summaries of incidents, allows follow-up questions, and offers recommended actions. This directly addresses the SOC analysts' need to quickly understand the full scope and use natural language, reducing investigation time.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Train the analysts to use Advanced Hunting to query across all data sources and build custom KQL queries to correlate the alerts.

    Why it's wrong here

    Advanced Hunting requires analysts to author KQL manually across tables, so it does not provide the natural-language incident summarisation, correlated alert graph or recommended actions requested. It is the right choice when analysts need bespoke, repeatable queries beyond what built-in investigation surfaces offer.

  • ✗

    Create custom detection rules in Microsoft Defender XDR to generate more specific alerts for similar activity.

    Why it's wrong here

    Custom detection rules generate additional alerts from query logic, adding to the alert volume rather than consolidating the existing incident into a correlated view with impacted assets and natural-language interrogation. They are the correct choice when you need recurring, tailored alerting for known activity patterns.

  • ✓

    Use Microsoft Copilot for Security integrated with Microsoft Defender XDR to get a natural language summary of the incident, ask follow-up questions, and receive recommended actions.

    Why this is correct

    Copilot for Security embedded in Defender XDR correlates the incident's alerts, entities and Defender for Identity signals, then answers natural-language questions and surfaces recommended actions. This directly satisfies the analysts' need to rapidly scope the incident across products without manual triage.

  • ✗

    Configure automated investigation and remediation to automatically contain the threat and then review the results.

    Why it's wrong here

    Automated investigation and remediation acts on alerts after they are raised, containing threats rather than surfacing the cross-workload incident graph, impacted assets and natural-language querying the analysts need. It is the right choice for unattended response at scale, not for interactive triage of a single high-severity incident.

Go deeper

Related to this question

About these practice questions

One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.