MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
Your organization uses Microsoft Defender for Endpoint (MDE). A security analyst needs to investigate a file that was detected as malicious on several devices. The analyst wants to see the file's prevalence across the organization and other related events. Which feature in MDE should the analyst use?
⚠ Common exam trap
Watch out — candidates often confuse the File page with the Alert page, thinking that alerts are the primary source for file prevalence data, but the File page is specifically designed to show file-level telemetry across the organization, not just alert-triggered events.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
File page
The File page in Microsoft Defender for Endpoint provides a comprehensive view of a specific file, including its prevalence across the organization, a list of devices where it was observed, and related events such as alerts and detections. This allows the security analyst to investigate the file's spread and associated incidents in one centralized location.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
File page
Why this is correct
The File page in Microsoft Defender for Endpoint is the authoritative location for examining a specific file's organizational footprint. It displays aggregated data on file prevalence across all onboarded devices, identifies every device where the file has been observed, and lists related events and alerts, enabling an analyst to assess the scope of a potential threat and investigate associated activity.
- ✗
Alert page
Why it's wrong here
The Alert page in Microsoft Defender for Endpoint is focused on the lifecycle and details of a single security alert, such as its severity, status, detection sources, and the chain of evidence that triggered it. While it does link to related files and devices, it does not provide an aggregated, organization-wide view of file prevalence, so it is unsuitable for determining how widely a file has appeared across the environment.
- ✗
Device page
Why it's wrong here
The Device page in Microsoft Defender for Endpoint provides deep telemetry for one specific machine, including its health state, installed software, vulnerabilities, and recent activities. It lists files that have been seen on that device only, and it cannot aggregate file prevalence across all devices or show related events from other parts of the organization. Therefore, it does not answer a question about overall file distribution.
- ✗
Investigation page
Why it's wrong here
The Investigation page in Microsoft Defender for Endpoint is dedicated to displaying the progress and results of automated investigations, including the actions taken, evidence gathered, and pending or completed remediation steps. It is a workflow-oriented view of an investigation, not a data view of file prevalence across devices, and it does not provide the file-centric prevalence and related-event information needed for this scenario.
Go deeper
Related to this question
About these practice questions
Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.