Courseiva

MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR

Your organization uses Microsoft Defender for Endpoint (Plan 2) and Microsoft Defender for Identity. A security analyst reports that several domain controllers are generating alerts for anomalous logon activity. You need to investigate the scope of the potential compromise across the entire environment, including endpoints, identities, and cloud apps. What is the most efficient approach?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use the Microsoft Defender XDR portal to view the unified incident

Microsoft Defender XDR provides a unified incident view that correlates alerts from all workloads. Option A is wrong because checking only endpoints misses identity and cloud app alerts. Option B is wrong because checking only identities misses endpoints. Option C is wrong because using multiple portals is inefficient.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Check each workload portal individually and correlate manually

    Why it's wrong here

    Checking each workload portal individually—such as Microsoft Defender for Endpoint, Defender for Identity, Defender for Office 365, and Defender for Cloud Apps—and then correlating the alerts manually is inefficient and error-prone. Alert timestamps, severity schemas, and naming conventions differ across portals, making it easy to miss a critical step in an attack chain. This approach forces analysts to manually reconstruct the entire attack story, which is exactly the automation that Microsoft Defender XDR provides.

  • ✗

    Review the alerts in Microsoft Defender for Identity only

    Why it's wrong here

    Reviewing only Microsoft Defender for Identity alerts narrows visibility to on-premises Active Directory and identity-focused signals, such as pass-the-hash or unusual Kerberos ticket activity. Many incidents begin in email, endpoint, or cloud apps and later manifest as identity compromise, so this limited telemetry fails to reveal the complete kill chain. The unified incident in Microsoft Defender XDR incorporates identity alerts alongside endpoint, email, and cloud app alerts to show the full scope of an attack.

  • ✗

    Review the alerts in Microsoft Defender for Endpoint only

    Why it's wrong here

    Looking only at Microsoft Defender for Endpoint alerts captures process, network, and file behaviors on devices, but it omits telemetry from identities, email, and SaaS applications. A security incident typically spans multiple surfaces, and the endpoint perspective might only expose the final payload or one detection event. Without the unified incident view, you could miss the initial access vector and lateral movement that occurred outside endpoint telemetry, leaving the response incomplete.

  • ✓

    Use the Microsoft Defender XDR portal to view the unified incident

    Why this is correct

    Use the Microsoft Defender XDR portal (formerly Microsoft 365 Defender) to view the unified incident, which automatically correlates alerts from all workloads—endpoint, identity, email, and cloud apps—into a single incident with an attack story. This portal provides affected assets, related alerts, evidence, and automated investigation timelines, allowing analysts to see the entire attack chain in one place. It also supports incident management actions such as commenting, assigning, and running automated responses across the integrated workloads.

About these practice questions

This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.