Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Microsoft logo

Microsoft 365 Certified:Administrator Expert

Domain 3Objective 1

Review and Respond to Security Reports and Alerts Generated by Microsoft Defender XDR MS-102 Practice Questions (Page 3)

Part of the Manage security and threats by using Microsoft Defender XDR domain, which accounts for 30–35% of the MS-102 exam. Microsoft does not publish an official question count, but from its 100-minute exam (~40–65 total, ~12–23 in this domain), expect 3–6 from this objective — we provide 34 practice questions to prepare you well beyond it. (estimate)

34questions here
7free pages
6concepts
30–35%of the exam

Questions 11–15

  1. 11application · medium

    A security analyst at Contoso is reviewing a Defender XDR alert that has been escalated to an incident. The analyst needs to gather additional evidence, such as all network connections made by the affected device in the last hour, to support the investigation. What should the analyst do?

    Select an answer first
  2. 12foundation · easy

    What is the primary purpose of Microsoft Security Exposure Management in the Microsoft Defender XDR portal?

    Select an answer first
  3. 13application · medium

    A security analyst at Contoso is investigating an alert about a potential phishing email that led to a user's credentials being compromised. The analyst wants to find all emails that contained the same malicious link sent to other users. Which advanced hunting query should the analyst use?

    Select an answer first
  4. 14application · medium

    A security analyst at Contoso receives a Defender XDR alert about a suspicious sign-in from an unfamiliar IP address. The analyst wants to quickly determine if this sign-in is part of a broader attack pattern affecting other users. Which action should the analyst take first?

    Select an answer first
  5. 15expert · hard

    A security analyst at Contoso is reviewing the Defender XDR report and notices a high volume of alerts from a specific device. The analyst wants to determine if the device is compromised or if the alerts are false positives. The analyst has limited time and needs to prioritize the investigation. Which approach should the analyst take?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Microsoft. “MS-102” is a trademark of its owner, used for identification only.