Courseiva

MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR

Your organization uses Microsoft Defender for Identity (MDI) and Microsoft Defender for Cloud Apps. You receive an alert about a user account that is exhibiting suspicious behavior: unusual login times from an IP address that is not in the user's typical location. The alert recommends action. You need to determine if the account is compromised. What is the best next step?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Initiate an automated investigation in Microsoft Defender XDR

Initiating an automated investigation in Microsoft Defender XDR correlates signals across MDI, Defender for Cloud Apps, and other Microsoft 365 services to determine if the account is compromised. Option B is wrong because configuring a conditional access policy is a preventive measure, not an investigative step to confirm compromise. Option C is wrong because disabling the account immediately might be premature and could disrupt legitimate access without confirming the threat. Option D is wrong because resetting the password alone does not investigate other potential malicious activity or identify the scope of compromise.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Initiate an automated investigation in Microsoft Defender XDR

    Why this is correct

    Automated investigation in Microsoft Defender XDR correlates the MDI sign-in anomaly with related alerts and entity data, gathering evidence and recommending remediation. This satisfies the need to determine compromise quickly without manually pivoting across portals.

  • ✗

    Configure a conditional access policy in Microsoft Entra ID to block the IP

    Why it's wrong here

    Blocking the IP in Microsoft Entra ID conditional access is a remediation step that presumes the sign-in is hostile and may block legitimate travel or VPN traffic. It is tempting because it stops the suspicious source, and would be correct once investigation confirms that address is malicious.

  • ✗

    Immediately disable the user account

    Why it's wrong here

    Disabling the account is a containment action taken after compromise is confirmed; it also destroys the live session evidence needed to determine whether the sign-in was genuine. It is tempting because disabling stops an active attacker, and would be correct once investigation confirms the account is compromised.

  • ✗

    Reset the user's password

    Why it's wrong here

    Resetting the password presumes compromise and locks the legitimate user out while erasing the session data investigators need; it does not determine whether the sign-in was malicious. It is tempting because credential reset is standard remediation, and would be correct after the investigation confirms the account was compromised.

Go deeper

Related to this question

About these practice questions

Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.