Courseiva

MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR

Your organization uses Microsoft Defender for Office 365. A user reports receiving a phishing email that bypassed the built-in anti-phishing policy. You need to analyze the email headers to determine why it was not detected. What should you use?

⚠ Common exam trap

MS-102 often tests the distinction between tools that show message routing (Message trace) versus tools that show detection verdicts and headers (Threat Explorer) — candidates confuse the two because both are email investigation tools.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Threat Explorer in Microsoft Defender for Office 365

Threat Explorer (part of Microsoft 365 Defender's Email & Collaboration section) provides detailed email metadata, including full message headers, delivery action, and the specific policy or filter that processed the message. It lets administrators trace why a message was allowed, blocked, or delivered to junk, and it surfaces the anti-phishing verdict, spoof intelligence, and detection technology that evaluated the message. This is the correct tool for post-incident header analysis of a phishing message that bypassed filtering.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Attack Simulator in Microsoft Defender for Office 365

    Why it's wrong here

    Attack Simulator launches simulated phishing campaigns to train users and report susceptibility; it generates no data about a real message's filtering. It is tempting because it directly involves phishing, and it is correct when measuring user awareness or testing organisational resilience.

  • ✓

    Threat Explorer in Microsoft Defender for Office 365

    Why this is correct

    Threat Explorer provides message trace, detection technology and delivery location per email, letting you determine which anti-phishing control failed and why. It is the Microsoft Defender for Office 365 tool built for investigating individual messages.

  • ✗

    Message trace in Exchange admin center

    Why it's wrong here

    Message trace reports delivery status and routing events, not the anti-phishing verdict or header authentication results needed here. It is tempting because it is the standard tool for tracking whether a message was delivered, which is correct when investigating mail flow rather than detection.

  • ✗

    Quarantine page in Microsoft Defender for Office 365

    Why it's wrong here

    The quarantine page lists and releases held messages; a message that bypassed filtering never appears there, and it exposes no header authentication detail. It is tempting because quarantine is where blocked phishing is managed, which is correct when releasing or deleting already-detained mail.

About these practice questions

This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.