Courseiva

MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR

Your organization uses Microsoft Defender for Identity (MDI) and Microsoft Defender for Cloud Apps. You receive an alert about a user who is performing an unusual number of failed logon attempts from a non-corporate IP address. The user is a member of the Finance group. What is the recommended first step?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Contact the user to verify if the activity is legitimate.

When an alert indicates unusual failed logon attempts from a non-corporate IP address, the recommended first step is to contact the user to verify if the activity is legitimate. This follows the principle of verification before action, as the activity could be due to a forgotten password or a misconfigured application. Option B is correct. Option A (resetting password and requiring MFA) is premature without verification, as it may disrupt legitimate access. Option C (disabling the account) could be too disruptive and should only be done after confirming malicious intent. Option D (blocking the IP) might block legitimate users or shared IPs. Option E (closing as false positive) skips investigation and could miss a real threat.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Reset the user's password and require MFA.

    Why it's wrong here

    Resetting the password and requiring MFA is containment, not triage; the recommended first step is investigating the alert in Microsoft Defender for Identity to confirm whether the failed logons are malicious. It is tempting because credential reset is the right response once compromise is confirmed.

  • ✓

    Contact the user to verify if the activity is legitimate.

    Why this is correct

    Verifying with the user confirms whether the failed logons are genuine mistyping or credential-stuffing before escalating. This satisfies the recommended first step, since contacting the account owner quickly establishes legitimacy without prematurely disabling a Finance user's access.

  • ✗

    Disable the user account immediately.

    Why it's wrong here

    Disabling the account immediately disrupts a Finance user's work before the alert is validated; the recommended first step is investigating the activity in Microsoft Defender for Identity. It is tempting because account disablement is the correct containment once compromise is confirmed.

  • ✗

    Block the IP address in the firewall.

    Why it's wrong here

    Blocking the source IP in the firewall acts before the alert is validated and may be evaded by rotating addresses; the first step is investigating the alert in Microsoft Defender for Identity. It is tempting because firewall blocking is a valid containment action after a confirmed external attack.

  • ✗

    Close the alert as a false positive.

    Why it's wrong here

    Closing the alert as a false positive skips verification, yet repeated failed logons from a non-corporate IP against a Finance account warrant investigation in Microsoft Defender for Identity. It is tempting because benign user error does generate such alerts, but only after evidence confirms it.

Go deeper

Related to this question

About these practice questions

Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.