Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Microsoft logo

Microsoft 365 Certified:Administrator Expert

Domain 3Objective 1

Review and Respond to Security Reports and Alerts Generated by Microsoft Defender XDR MS-102 Practice Questions (Page 4)

Part of the Manage security and threats by using Microsoft Defender XDR domain, which accounts for 30–35% of the MS-102 exam. Microsoft does not publish an official question count, but from its 100-minute exam (~40–65 total, ~12–23 in this domain), expect 3–6 from this objective — we provide 34 practice questions to prepare you well beyond it. (estimate)

34questions here
7free pages
6concepts
30–35%of the exam

Questions 16–20

  1. 16application · medium

    A security analyst at Fabrikam needs to identify all devices that are exposed to a newly disclosed critical vulnerability. The analyst also wants to see which of those devices have been involved in any suspicious activity. What should the analyst do?

    Select an answer first
  2. 17application · medium

    A security administrator at Fabrikam reviews the weekly Defender XDR report and sees that the number of devices with a high-severity vulnerability has increased. The administrator wants to reduce this number by prioritizing the most impactful remediation actions. What should the administrator do?

    Select an answer first
  3. 18expert · hard

    A security administrator at Contoso is reviewing a high-severity Defender XDR alert that was automatically closed as a false positive. The administrator suspects the alert was actually a true positive but was suppressed by a custom detection rule. The administrator needs to confirm the alert's validity and ensure future alerts are not suppressed. What should the administrator do?

    Select an answer first
  4. 19expert · hard

    A security administrator at Fabrikam notices that the weekly Defender XDR report shows a high number of alerts that were automatically resolved without investigation. The administrator wants to reduce the number of auto-resolved alerts while ensuring that genuine threats are not missed. What should the administrator do?

    Select an answer first
  5. 20expert · hard

    A security administrator at Fabrikam reviews the monthly Defender XDR report and sees an increase in alerts related to a specific threat actor. The administrator wants to understand the actor's tactics and techniques and determine if any of their assets are at risk. What should the administrator do?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Microsoft. “MS-102” is a trademark of its owner, used for identification only.