MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
Your organization uses Microsoft Defender for Identity. You receive an alert about a suspicious LDAP query from a domain controller. After investigating, you determine the query is legitimate. How should you prevent future alerts for this activity?
⚠ Common exam trap
MS-102 often tests the difference between suppressing a specific alert (scoped to alert type + entity) and disabling the sensor or detection entirely — candidates who pick the 'disable' option fail to recognize that suppression is the surgical, non-disruptive fix.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a suppression rule for that alert type and entity.
Microsoft Defender for Identity suppression rules are the designed mechanism for silencing alerts that have been triaged as benign. A suppression rule scoped to the specific alert type (e.g., 'Suspicious LDAP query') and the specific entity (the domain controller or account) prevents future identical alerts from being raised without weakening detection for the rest of the environment. This preserves the integrity of the detection pipeline while eliminating noise from known-good activity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create a suppression rule for that alert type and entity.
Why this is correct
Suppression rules in Microsoft Defender for Identity silence matching alerts by type and entity, so the confirmed-benign LDAP query from that domain controller stops generating alerts. This satisfies the stem's requirement to prevent future alerts for legitimate activity.
- ✗
Create a custom detection rule to allow the LDAP query.
Why it's wrong here
Defender for Identity has no custom detection rule type for allowing LDAP queries; exclusions are configured as detection exclusions in the portal. Custom detections create new alerts from your own logic, useful for organisation-specific threats, not for suppressing an existing built-in detection.
- ✗
Disable the Defender for Identity sensor on the domain controller.
Why it's wrong here
Disabling the sensor halts all Defender for Identity monitoring on that domain controller, so genuine malicious LDAP activity would also go undetected. It is tempting as a quick way to silence a noisy alert source, and would be correct only when decommissioning the server or troubleshooting sensor faults.
- ✗
Change the alert severity to Low.
Why it's wrong here
Lowering severity leaves the alert generating and visible, merely reclassified, so the legitimate query still triggers future notifications. Severity tuning suits triage prioritisation across many alerts, not suppression of a specific known-benign activity, which requires an exclusion.
Go deeper
Related to this question
About these practice questions
One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.