MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
Your organization uses Microsoft Defender for Office 365. A user reports receiving a phishing email that bypassed the built-in anti-phishing policy. You need to analyze the email headers to determine why it was not detected. What should you use?
⚠ Common exam trap
MS-102 often tests the distinction between tools that show message routing (Message trace) versus tools that show detection verdicts and headers (Threat Explorer) — candidates confuse the two because both are email investigation tools.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Threat Explorer in Microsoft Defender for Office 365
Threat Explorer (part of Microsoft 365 Defender's Email & Collaboration section) provides detailed email metadata, including full message headers, delivery action, and the specific policy or filter that processed the message. It lets administrators trace why a message was allowed, blocked, or delivered to junk, and it surfaces the anti-phishing verdict, spoof intelligence, and detection technology that evaluated the message. This is the correct tool for post-incident header analysis of a phishing message that bypassed filtering.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Attack Simulator in Microsoft Defender for Office 365
Why it's wrong here
Attack Simulator launches simulated phishing campaigns to train users and report susceptibility; it generates no data about a real message's filtering. It is tempting because it directly involves phishing, and it is correct when measuring user awareness or testing organisational resilience.
- ✓
Threat Explorer in Microsoft Defender for Office 365
Why this is correct
Threat Explorer provides message trace, detection technology and delivery location per email, letting you determine which anti-phishing control failed and why. It is the Microsoft Defender for Office 365 tool built for investigating individual messages.
- ✗
Message trace in Exchange admin center
Why it's wrong here
Message trace reports delivery status and routing events, not the anti-phishing verdict or header authentication results needed here. It is tempting because it is the standard tool for tracking whether a message was delivered, which is correct when investigating mail flow rather than detection.
- ✗
Quarantine page in Microsoft Defender for Office 365
Why it's wrong here
The quarantine page lists and releases held messages; a message that bypassed filtering never appears there, and it exposes no header authentication detail. It is tempting because quarantine is where blocked phishing is managed, which is correct when releasing or deleting already-detained mail.
Go deeper
Related to this question
Learn chapter
Threat Analytics Dashboard
Key term
Threat Explorer
A Microsoft 365 security tool that provides real-time interactive reports to investigate and analyze threats detected by Microsoft Defender for Office 365.
Key term
Threat
A threat is any potential danger that could harm a computer system, network, or data, whether from a malicious hacker, a natural disaster, or an accidental mistake.
About these practice questions
This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.