Courseiva

MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR

Your organization uses Microsoft Defender for Identity. You receive an alert about a suspicious Kerberos ticket request. You need to investigate which user account is potentially compromised. Which tool should you use to correlate the alert with user activity?

⚠ Common exam trap

Watch out — candidates often confuse the Microsoft Entra admin center (which handles identity configuration) with the Microsoft Defender XDR portal (which handles security incident correlation), leading them to choose D instead of A.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Defender XDR portal

The Microsoft Defender XDR portal (security.microsoft.com) provides a unified incident queue that correlates alerts from Defender for Identity with user activity, including Kerberos ticket requests. This allows you to investigate the specific user account involved by examining the alert timeline, related events, and entity details such as the account's authentication patterns and potential lateral movement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Microsoft Defender XDR portal

    Why this is correct

    The Microsoft Defender XDR portal (security.microsoft.com) is the correct console because it unifies alerts from Defender for Identity with Defender for Endpoint, Defender for Office 365, and Defender for Cloud Apps into a single incident queue and entity timeline. Identity-related alerts—such as suspicious Kerberos authentication, LAN-LAN traffic, or privilege escalation—are ingested from Defender for Identity sensors on domain controllers and correlated to show attack narratives like lateral movement. This cross-domain correlation is what makes it the central place to investigate and respond to identity threats.

  • ✗

    Microsoft Intune admin center

    Why it's wrong here

    The Microsoft Intune admin center is focused on mobile device management (MDM) and mobile application management (MAM) for Windows, iOS, Android, and macOS devices. While it can show device compliance and conditional access status, it lacks the security analytics engine and incident correlation that Defender for Identity alerts require. It also does not ingest identity authentication metadata from domain controllers, so it cannot display suspicious account activities or compromised credential paths.

  • ✗

    Microsoft Purview compliance portal

    Why it's wrong here

    Microsoft Purview's compliance portal is dedicated to information protection, data-loss prevention, eDiscovery, and audit log search, serving legal and regulatory requirements. Although it contains unified audit logs that might include some identity events, it is not an incident-management or threat-investigation workspace. Defender for Identity alerts have no native queue or incident correlation inside Purview; its role is retrospective compliance, not live security operations.

  • ✗

    Microsoft Entra admin center

    Why it's wrong here

    The Microsoft Entra admin center handles directory administration, user provisioning, self-service password reset, and conditional access policies, and it does show Microsoft Entra Identity Protection risk events. However, those risk detections are not the same as Defender for Identity alerts and are not correlated with endpoint or email telemetry in a unified incident view. For full attack-chain reconstruction—especially where Defender for Identity sensors monitor domain controllers—you must use the Microsoft Defender XDR portal rather than Entra.

About these practice questions

This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.