Courseiva

MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR

Your organization uses Microsoft Defender for Endpoint (MDE). A security analyst needs to investigate a file that was detected as malicious on several devices. The analyst wants to see the file's prevalence across the organization and other related events. Which feature in MDE should the analyst use?

⚠ Common exam trap

Watch out — candidates often confuse the File page with the Alert page, thinking that alerts are the primary source for file prevalence data, but the File page is specifically designed to show file-level telemetry across the organization, not just alert-triggered events.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

File page

The File page in Microsoft Defender for Endpoint provides a comprehensive view of a specific file, including its prevalence across the organization, a list of devices where it was observed, and related events such as alerts and detections. This allows the security analyst to investigate the file's spread and associated incidents in one centralized location.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    File page

    Why this is correct

    The File page in Microsoft Defender for Endpoint is the authoritative location for examining a specific file's organizational footprint. It displays aggregated data on file prevalence across all onboarded devices, identifies every device where the file has been observed, and lists related events and alerts, enabling an analyst to assess the scope of a potential threat and investigate associated activity.

  • ✗

    Alert page

    Why it's wrong here

    The Alert page in Microsoft Defender for Endpoint is focused on the lifecycle and details of a single security alert, such as its severity, status, detection sources, and the chain of evidence that triggered it. While it does link to related files and devices, it does not provide an aggregated, organization-wide view of file prevalence, so it is unsuitable for determining how widely a file has appeared across the environment.

  • ✗

    Device page

    Why it's wrong here

    The Device page in Microsoft Defender for Endpoint provides deep telemetry for one specific machine, including its health state, installed software, vulnerabilities, and recent activities. It lists files that have been seen on that device only, and it cannot aggregate file prevalence across all devices or show related events from other parts of the organization. Therefore, it does not answer a question about overall file distribution.

  • ✗

    Investigation page

    Why it's wrong here

    The Investigation page in Microsoft Defender for Endpoint is dedicated to displaying the progress and results of automated investigations, including the actions taken, evidence gathered, and pending or completed remediation steps. It is a workflow-oriented view of an investigation, not a data view of file prevalence across devices, and it does not provide the file-centric prevalence and related-event information needed for this scenario.

About these practice questions

Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.