Courseiva

MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR

Your organization uses Microsoft Defender XDR and Microsoft 365 E5 licenses. You need to ensure that when a user reports a phishing email using the Microsoft Report Message add-in, the email is automatically submitted to Microsoft for analysis and the user is notified of the analysis result. You want to minimize administrative effort. What should you do?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

In Microsoft Defender XDR, go to Settings > Email & collaboration > User reported messages, and enable 'Send reported messages to Microsoft' and 'Notify users when analysis completes'.

The user-reported messages settings in Microsoft Defender XDR (Settings > Email & collaboration > User reported messages) allow you to automatically send reported messages to Microsoft for analysis and notify users when analysis completes, minimizing administrative effort. Option A is wrong because a mail flow rule would only forward messages to a security team mailbox, not to Microsoft, and would not provide automatic analysis or user notification. Option B is wrong because simply configuring the Report Message add-in for all users enables reporting but does not by itself automatically submit to Microsoft or notify users; the Defender XDR settings are required for those actions. Option C is wrong because manually submitting each reported email via the Microsoft 365 Defender portal defeats the goal of minimizing administrative effort and does not automatically notify the user of results.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a mail flow rule that forwards reported messages to a security team mailbox.

    Why it's wrong here

    A mail flow rule only routes reported messages to a mailbox; it neither submits them to Microsoft for analysis nor notifies the reporting user of a verdict. It is tempting because transport rules are the standard mechanism for capturing and archiving reported mail for a security team to triage manually.

  • ✗

    Configure the Microsoft Report Message add-in for all users.

    Why it's wrong here

    Deploying the add-in gives users a reporting button but does not configure the submission pipeline that sends reports to Microsoft and returns verdicts to reporters. It is tempting because add-in deployment is a genuine prerequisite, and in tenants without E5 it would be the available step.

  • ✗

    Use the Microsoft 365 Defender portal to manually submit the email for analysis whenever a user reports it.

    Why it's wrong here

    Manual submission requires an administrator to act each time a user reports a message, which fails the minimise-administrative-effort requirement and delays user notification. It is tempting because manual submission is genuinely useful for one-off investigations of suspicious messages that automated tooling has not flagged.

  • ✓

    In Microsoft Defender XDR, go to Settings > Email & collaboration > User reported messages, and enable 'Send reported messages to Microsoft' and 'Notify users when analysis completes'.

    Why this is correct

    Enabling 'Send reported messages to Microsoft' and 'Notify users when analysis completes' in the User reported messages settings routes reports automatically and returns verdicts to users, satisfying the minimal administrative effort constraint without custom flows or policies.

Go deeper

Related to this question

About these practice questions

This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.