MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
Your organization uses Microsoft Defender for Identity (MDI) and Microsoft Defender for Cloud Apps. You receive an alert about a user account that is exhibiting suspicious behavior: unusual login times from an IP address that is not in the user's typical location. The alert recommends action. You need to determine if the account is compromised. What is the best next step?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Initiate an automated investigation in Microsoft Defender XDR
Initiating an automated investigation in Microsoft Defender XDR correlates signals across MDI, Defender for Cloud Apps, and other Microsoft 365 services to determine if the account is compromised. Option B is wrong because configuring a conditional access policy is a preventive measure, not an investigative step to confirm compromise. Option C is wrong because disabling the account immediately might be premature and could disrupt legitimate access without confirming the threat. Option D is wrong because resetting the password alone does not investigate other potential malicious activity or identify the scope of compromise.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Initiate an automated investigation in Microsoft Defender XDR
Why this is correct
Automated investigation in Microsoft Defender XDR correlates the MDI sign-in anomaly with related alerts and entity data, gathering evidence and recommending remediation. This satisfies the need to determine compromise quickly without manually pivoting across portals.
- ✗
Configure a conditional access policy in Microsoft Entra ID to block the IP
Why it's wrong here
Blocking the IP in Microsoft Entra ID conditional access is a remediation step that presumes the sign-in is hostile and may block legitimate travel or VPN traffic. It is tempting because it stops the suspicious source, and would be correct once investigation confirms that address is malicious.
- ✗
Immediately disable the user account
Why it's wrong here
Disabling the account is a containment action taken after compromise is confirmed; it also destroys the live session evidence needed to determine whether the sign-in was genuine. It is tempting because disabling stops an active attacker, and would be correct once investigation confirms the account is compromised.
- ✗
Reset the user's password
Why it's wrong here
Resetting the password presumes compromise and locks the legitimate user out while erasing the session data investigators need; it does not determine whether the sign-in was malicious. It is tempting because credential reset is standard remediation, and would be correct after the investigation confirms the account was compromised.
Go deeper
Related to this question
Learn chapter
Privileged Identity Management (PIM) for Admins
Key term
XDR
XDR, or Extended Detection and Response, is a unified security platform that collects and correlates data across multiple security layers—endpoints, networks, servers, cloud workloads, and email—to improve threat detection and enable faster response.
Key term
Conditional access
Conditional access is a security framework that evaluates signals like user location, device health, and risk level to grant or block access to resources in real time.
About these practice questions
Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.