Microsoft MS-102 Defender XDR Incidents Alerts Reports Advanced Hunting And Threat Intelligence Practice Test

 

MS-102 skills 3.1 | 30 original questions

This MS-102 practice set focuses on defender xdr incidents alerts reports advanced hunting and threat intelligence through original scenario-based questions aligned to Microsoft skills measured as of April 28, 2026. Use the full ExamSnap MS-102 collection for practice across all four current skill areas. For broader exam preparation, review the Microsoft MS-102 Exam Dumps page.

Instructions: Select the best answer for each question. Review the rationale after answering. Each distractor includes a brief explanation of why it is not the strongest fit for the stated scenario.

Question 1

An incident review at Adventure Works produces a single administrative requirement for the compliance administrator. A production change is approved only if it can correlate related alerts, affected entities, and evidence before responding to a multi-stage attack. The design should minimize manual per-user administration where a scoped central control exists. The service desk has 11 related tickets from 23 business units, so the team wants a targeted fix. Which control should the team use?

  1. Create an activity policy in Defender for Cloud Apps with an alert
  2. Mark the risky discovered app as unsanctioned and use supported enforcement integration where appropriate
  3. Use Microsoft Security Exposure Management to investigate exposure paths and initiatives
  4. Investigate the incident in the Microsoft Defender portal
  5. Create a Microsoft Defender for Office 365 alert policy

Correct answer: D

Why: Defender XDR incidents aggregate related alerts and evidence across supported products, giving responders a coordinated investigation view. It directly addresses the stated requirement.

Option review:

A: Activity policies evaluate cloud activity criteria and can trigger alerts when matching events occur. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Unsanctioning identifies disallowed apps and can integrate with supported controls to help restrict their use. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Security Exposure Management helps connect exposure signals into attack paths and initiatives, supporting risk-based prioritization beyond isolated findings. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Defender XDR incidents aggregate related alerts and evidence across supported products, giving responders a coordinated investigation view. It directly addresses the stated requirement.

E: Alert policies define the conditions and notification behavior for security events that should create administrator alerts. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T13-Q001: Investigate the incident in the Microsoft Defender portal – Defender XDR incidents aggregate related alerts and evidence across supported products, giving responders a coordinated investigation view.

Question 2

The governance lead at Trey Research is designing the next phase of the Microsoft 365 rollout. Before the tenant expands to another business unit, the administrator must search raw Defender XDR event data for a hypothesis that is not answered by the standard incident view. The control owner requires a review after 28 days and evidence from 13 representative cases. The solution should use a native Microsoft control that matches the stated requirement. Which option best satisfies the requirement?

  1. Configure a Safe Attachments policy
  2. Review simulation results to identify users or techniques that need additional training
  3. Prioritize the vulnerability recommendation with the highest risk and exposure impact
  4. Create an activity policy in Defender for Cloud Apps with an alert
  5. Use advanced hunting with KQL

Correct answer: E

Why: Advanced hunting supports flexible KQL queries across Defender XDR schema tables for proactive or investigation-driven searches. It directly addresses the stated requirement.

Option review:

A: Safe Attachments provides additional protection against unknown malicious attachments beyond signature-based malware detection. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Simulation metrics show interaction patterns and training outcomes that can guide follow-up education and future campaign design. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Defender Vulnerability Management combines vulnerability, threat, exposure, and asset context to help prioritize remediation rather than ranking by CVE count alone. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Activity policies evaluate cloud activity criteria and can trigger alerts when matching events occur. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Advanced hunting supports flexible KQL queries across Defender XDR schema tables for proactive or investigation-driven searches. It directly addresses the stated requirement.

Learning point: MS102-T13-Q002: Use advanced hunting with KQL – Advanced hunting supports flexible KQL queries across Defender XDR schema tables for proactive or investigation-driven searches.

Question 3

An incident review at Woodgrove Bank produces a single administrative requirement for the identity administrator. Before the tenant expands to another business unit, the administrator must correlate related alerts, affected entities, and evidence before responding to a multi-stage attack. The initial rollout covers 3 locations and approximately 450 managed identities or devices. The administrator must avoid granting unrelated tenant-wide privilege. Which option best satisfies the requirement?

  1. Investigate the incident in the Microsoft Defender portal
  2. Connect Microsoft 365 to Microsoft Defender for Cloud Apps with the app connector
  3. Integrate Defender for Endpoint signals with Cloud App Discovery when endpoints are the chosen visibility source
  4. Correlate a suspicious indicator with Defender Threat Intelligence before blocking it broadly
  5. Configure a Safe Attachments policy

Correct answer: A

Why: Defender XDR incidents aggregate related alerts and evidence across supported products, giving responders a coordinated investigation view. It directly addresses the stated requirement.

Option review:

A: Defender XDR incidents aggregate related alerts and evidence across supported products, giving responders a coordinated investigation view. It directly addresses the stated requirement.

B: The Microsoft 365 app connector supplies supported activity and governance integration to Defender for Cloud Apps. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Defender for Endpoint integration can supply endpoint-based cloud app usage signals to Cloud App Discovery without requiring only perimeter firewall logs. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Threat-intelligence context can reduce false assumptions and reveal related infrastructure before a high-impact blocking decision is made. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Safe Attachments provides additional protection against unknown malicious attachments beyond signature-based malware detection. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T13-Q003: Investigate the incident in the Microsoft Defender portal – Defender XDR incidents aggregate related alerts and evidence across supported products, giving responders a coordinated investigation view.

Question 4

Margie Travel is preparing a change requested by the security operations analyst. A production change is approved only if it can search raw Defender XDR event data for a hypothesis that is not answered by the standard incident view. The organization wants a reversible rollout with measurable verification before broad enforcement. The affected scope contains 62 users across 16 administrative groups. What is the most appropriate next step?

  1. Use exposure initiatives to measure progress toward a defined security objective
  2. Use advanced hunting with KQL
  3. Use quarantine and remediation actions for confirmed malicious messages
  4. Configure Defender for Endpoint settings in the Microsoft Defender portal
  5. Connect Microsoft 365 to Microsoft Defender for Cloud Apps with the app connector

Correct answer: B

Why: Advanced hunting supports flexible KQL queries across Defender XDR schema tables for proactive or investigation-driven searches. It directly addresses the stated requirement.

Option review:

A: Exposure initiatives organize related recommendations around measurable security objectives, making them better suited than isolated alerts for posture improvement programs. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Advanced hunting supports flexible KQL queries across Defender XDR schema tables for proactive or investigation-driven searches. It directly addresses the stated requirement.

C: Quarantine and message remediation actions remove or restrict access to malicious content without relying on users to delete messages manually. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Endpoint settings in the Defender portal govern service features and integrations rather than requiring per-device manual changes for every capability. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: The Microsoft 365 app connector supplies supported activity and governance integration to Defender for Cloud Apps. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T13-Q004: Use advanced hunting with KQL – Advanced hunting supports flexible KQL queries across Defender XDR schema tables for proactive or investigation-driven searches.

Question 5

Northwind Traders is standardizing administration after several teams used inconsistent procedures. A post-incident action item requires the tenant to correlate related alerts, affected entities, and evidence before responding to a multi-stage attack. The initial rollout covers 6 locations and approximately 790 managed identities or devices. The team wants evidence from the Microsoft 365 or Microsoft Entra control plane rather than assumptions. Which approach most directly addresses the requirement?

  1. Reassess the recommendation after remediation to verify exposure decreased
  2. Pivot from a suspicious activity-log event to the related user or app context
  3. Investigate the incident in the Microsoft Defender portal
  4. Drill from a Defender XDR report finding into the underlying security data
  5. Use exposure initiatives to measure progress toward a defined security objective

Correct answer: C

Why: Defender XDR incidents aggregate related alerts and evidence across supported products, giving responders a coordinated investigation view. It directly addresses the stated requirement.

Option review:

A: Closing a change ticket is not proof of risk reduction; Defender Vulnerability Management should reflect improved exposure after telemetry updates. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Activity-log records are more useful when correlated with the involved user, app, IP, and adjacent events instead of reviewed as standalone lines. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Defender XDR incidents aggregate related alerts and evidence across supported products, giving responders a coordinated investigation view. It directly addresses the stated requirement.

D: Reports identify patterns or issues; responders should use the related detailed records or incidents to determine the cause and required action. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Exposure initiatives organize related recommendations around measurable security objectives, making them better suited than isolated alerts for posture improvement programs. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T13-Q005: Investigate the incident in the Microsoft Defender portal – Defender XDR incidents aggregate related alerts and evidence across supported products, giving responders a coordinated investigation view.

Question 6

Humongous Insurance is preparing a change requested by the messaging administrator. The service owner wants a supportable design that will search raw Defender XDR event data for a hypothesis that is not answered by the standard incident view. The team wants evidence from the Microsoft 365 or Microsoft Entra control plane rather than assumptions. The team will validate the change with 19 pilot groups before expanding it to 5 users. What should the administrator configure first?

  1. Prioritize remediation by exposure and business context rather than score alone
  2. Tune alert policy thresholds or recipients instead of weakening threat protection
  3. Use the supported Defender for Endpoint onboarding method for the device-management platform
  4. Use advanced hunting with KQL
  5. Reassess the recommendation after remediation to verify exposure decreased

Correct answer: D

Why: Advanced hunting supports flexible KQL queries across Defender XDR schema tables for proactive or investigation-driven searches. It directly addresses the stated requirement.

Option review:

A: Secure Score is a posture indicator, not a complete risk model; exposure, asset criticality, and exploitability should inform remediation priority. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Alerting and threat protection are separate concerns; changing the alert policy can reduce notification noise without disabling the protection itself. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Defender for Endpoint provides multiple supported onboarding methods; choosing one aligned to the management platform improves consistency and verification. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Advanced hunting supports flexible KQL queries across Defender XDR schema tables for proactive or investigation-driven searches. It directly addresses the stated requirement.

E: Closing a change ticket is not proof of risk reduction; Defender Vulnerability Management should reflect improved exposure after telemetry updates. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T13-Q006: Use advanced hunting with KQL – Advanced hunting supports flexible KQL queries across Defender XDR schema tables for proactive or investigation-driven searches.

Question 7

Blue Yonder Airlines is migrating a business process to Microsoft 365 and wants the narrowest supported solution. A controlled pilot must demonstrate how to correlate related alerts, affected entities, and evidence before responding to a multi-stage attack. The solution should use a native Microsoft control that matches the stated requirement. The affected scope contains 22 users across 9 administrative groups. What should the administrator configure first?

  1. Create and track a remediation activity from the vulnerability recommendation
  2. Use an anomaly detection or app discovery policy when the requirement is behavior- or discovery-driven
  3. Use advanced hunting with KQL
  4. Prioritize remediation by exposure and business context rather than score alone
  5. Investigate the incident in the Microsoft Defender portal

Correct answer: E

Why: Defender XDR incidents aggregate related alerts and evidence across supported products, giving responders a coordinated investigation view. It directly addresses the stated requirement.

Option review:

A: Remediation workflows let security teams request, track, and validate vulnerability fixes instead of treating recommendations as a static report. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Defender for Cloud Apps offers policy types tailored to activity anomalies and discovered-app governance scenarios. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Advanced hunting supports flexible KQL queries across Defender XDR schema tables for proactive or investigation-driven searches. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Secure Score is a posture indicator, not a complete risk model; exposure, asset criticality, and exploitability should inform remediation priority. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Defender XDR incidents aggregate related alerts and evidence across supported products, giving responders a coordinated investigation view. It directly addresses the stated requirement.

Learning point: MS102-T13-Q007: Investigate the incident in the Microsoft Defender portal – Defender XDR incidents aggregate related alerts and evidence across supported products, giving responders a coordinated investigation view.

Question 8

The security operations analyst at City Power & Light is designing the next phase of the Microsoft 365 rollout. An internal assessment finds the control technically functional but unable to search raw Defender XDR event data for a hypothesis that is not answered by the standard incident view. The service desk has 39 related tickets from 22 business units, so the team wants a targeted fix. The administrator must avoid granting unrelated tenant-wide privilege. Which option best satisfies the requirement?

  1. Use advanced hunting with KQL
  2. Review Microsoft Secure Score improvement actions
  3. Use preset security policies when a standardized Microsoft-recommended protection baseline meets the requirement
  4. Review the restricted entities page for the blocked user
  5. Create and track a remediation activity from the vulnerability recommendation

Correct answer: A

Why: Advanced hunting supports flexible KQL queries across Defender XDR schema tables for proactive or investigation-driven searches. It directly addresses the stated requirement.

Option review:

A: Advanced hunting supports flexible KQL queries across Defender XDR schema tables for proactive or investigation-driven searches. It directly addresses the stated requirement.

B: Secure Score surfaces recommended security actions and scoring so administrators can prioritize improvements and track security posture progress. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Preset security policies bundle recommended configurations and can accelerate deployment of Standard or Strict protection baselines. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Restricted entities identifies users or other entities blocked because of suspicious or abusive sending behavior and supports controlled remediation. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Remediation workflows let security teams request, track, and validate vulnerability fixes instead of treating recommendations as a static report. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T13-Q008: Use advanced hunting with KQL – Advanced hunting supports flexible KQL queries across Defender XDR schema tables for proactive or investigation-driven searches.

Question 9

During a tenant review at Coho Winery, the Microsoft 365 administrator identifies one unresolved requirement. The administrator must choose between several Microsoft 365 controls. Only one directly meets the documented need to correlate related alerts, affected entities, and evidence before responding to a multi-stage attack. The response must address the cause described in the scenario rather than simply suppressing the symptom. The affected scope contains 56 users across 12 administrative groups. What should the administrator configure first?

  1. Use device groups or supported scoped settings when different endpoint populations require different treatment
  2. Investigate the incident in the Microsoft Defender portal
  3. Validate the app connector status and granted permissions
  4. Review the discovered app risk score and usage before sanctioning or unsanctioning it
  5. Review Microsoft Secure Score improvement actions

Correct answer: B

Why: Defender XDR incidents aggregate related alerts and evidence across supported products, giving responders a coordinated investigation view. It directly addresses the stated requirement.

Option review:

A: Scoped endpoint administration helps align settings and response permissions to device populations and operational responsibilities. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Defender XDR incidents aggregate related alerts and evidence across supported products, giving responders a coordinated investigation view. It directly addresses the stated requirement.

C: A connector that is disabled, unhealthy, or missing required permissions can prevent expected activity from appearing. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Cloud App Discovery provides app risk information and usage context that should inform governance decisions instead of blocking solely because an app is unfamiliar. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Secure Score surfaces recommended security actions and scoring so administrators can prioritize improvements and track security posture progress. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T13-Q009: Investigate the incident in the Microsoft Defender portal – Defender XDR incidents aggregate related alerts and evidence across supported products, giving responders a coordinated investigation view.

Question 10

Contoso Retail is troubleshooting a Microsoft 365 behavior that affects a limited but important user population. The implementation review is focused on one outcome: search raw Defender XDR event data for a hypothesis that is not answered by the standard incident view. The team will validate the change with 2 pilot groups before expanding it to 73 users. The team does not want to redesign unrelated workloads. Which administrative choice should be recommended?

  1. Use Microsoft Defender Threat Intelligence for threat actor and indicator context
  2. Configure a Safe Links policy
  3. Use advanced hunting with KQL
  4. Create an Attack Simulation Training campaign
  5. Use device groups or supported scoped settings when different endpoint populations require different treatment

Correct answer: C

Why: Advanced hunting supports flexible KQL queries across Defender XDR schema tables for proactive or investigation-driven searches. It directly addresses the stated requirement.

Option review:

A: Defender Threat Intelligence provides intelligence context that helps analysts understand indicators and threat infrastructure beyond tenant telemetry alone. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Safe Links evaluates URLs and can block malicious destinations at click time, addressing link-based phishing threats. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Advanced hunting supports flexible KQL queries across Defender XDR schema tables for proactive or investigation-driven searches. It directly addresses the stated requirement.

D: Attack Simulation Training lets security teams run controlled simulations and associate training with the simulated attack experience. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Scoped endpoint administration helps align settings and response permissions to device populations and operational responsibilities. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T13-Q010: Use advanced hunting with KQL – Advanced hunting supports flexible KQL queries across Defender XDR schema tables for proactive or investigation-driven searches.

Question 11

During a tenant review at Tailspin Toys, the security operations analyst identifies one unresolved requirement. An internal assessment finds the control technically functional but unable to review recurring security patterns and operational trends across the environment. The initial rollout covers 15 locations and approximately 900 managed identities or devices. The team must preserve a clear audit trail for the administrative decision. Which option best satisfies the requirement?

  1. Verify the device appears in Defender for Endpoint device inventory after onboarding
  2. Use threat and exploit context when prioritizing two vulnerabilities with similar severity
  3. Use Cloud App Discovery data from supported endpoint or network traffic sources
  4. Use Microsoft Defender XDR reports for trend and coverage analysis
  5. Use Microsoft Defender Threat Intelligence for threat actor and indicator context

Correct answer: D

Why: Defender XDR reports summarize security posture, activity, and trends in ways that complement event-level investigations. It directly addresses the stated requirement.

Option review:

A: Successful script execution alone does not prove service connectivity; device inventory and sensor health provide evidence that onboarding completed. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Severity alone can be insufficient; active exploitation signals and organizational exposure provide stronger prioritization context. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Cloud App Discovery analyzes observed cloud traffic to identify applications and usage rather than relying only on an administrator-maintained application list. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Defender XDR reports summarize security posture, activity, and trends in ways that complement event-level investigations. It directly addresses the stated requirement.

E: Defender Threat Intelligence provides intelligence context that helps analysts understand indicators and threat infrastructure beyond tenant telemetry alone. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T13-Q011: Use Microsoft Defender XDR reports for trend and coverage analysis – Defender XDR reports summarize security posture, activity, and trends in ways that complement event-level investigations.

Question 12

Southridge Video is standardizing administration after several teams used inconsistent procedures. The administrator must choose between several Microsoft 365 controls. Only one directly meets the documented need to investigate the specific issue behind an unfavorable report trend. Existing workload settings should remain unchanged unless the requirement specifically depends on them. The affected scope contains 16 users across 5 administrative groups. What should the administrator configure first?

  1. Use advanced hunting with KQL
  2. Assign and track improvement work from the Secure Score recommendation context
  3. Use Threat Explorer or Real-time detections to investigate the malicious message campaign
  4. Verify the device appears in Defender for Endpoint device inventory after onboarding
  5. Drill from a Defender XDR report finding into the underlying security data

Correct answer: E

Why: Reports identify patterns or issues; responders should use the related detailed records or incidents to determine the cause and required action. It directly addresses the stated requirement.

Option review:

A: Advanced hunting supports flexible KQL queries across Defender XDR schema tables for proactive or investigation-driven searches. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Secure Score recommendations provide context for remediation and progress tracking instead of requiring administrators to infer actions from raw alert counts. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Defender for Office 365 investigation tools provide message-level campaign and detection details needed to scope and respond to email threats. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Successful script execution alone does not prove service connectivity; device inventory and sensor health provide evidence that onboarding completed. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Reports identify patterns or issues; responders should use the related detailed records or incidents to determine the cause and required action. It directly addresses the stated requirement.

Learning point: MS102-T13-Q012: Drill from a Defender XDR report finding into the underlying security data – Reports identify patterns or issues; responders should use the related detailed records or incidents to determine the cause and required action.

Question 13

The service desk lead at Consolidated Messenger is designing the next phase of the Microsoft 365 rollout. Before the tenant expands to another business unit, the administrator must review recurring security patterns and operational trends across the environment. The initial rollout covers 18 locations and approximately 330 managed identities or devices. The change must be repeatable and supportable after the project team leaves. What is the most appropriate next step?

  1. Use Microsoft Defender XDR reports for trend and coverage analysis
  2. Secure the compromised account before removing the sending restriction
  3. Review exposed devices for the recommendation before scheduling the fix
  4. Filter the Defender for Cloud Apps activity log by user, IP address, activity, or application
  5. Use advanced hunting with KQL

Correct answer: A

Why: Defender XDR reports summarize security posture, activity, and trends in ways that complement event-level investigations. It directly addresses the stated requirement.

Option review:

A: Defender XDR reports summarize security posture, activity, and trends in ways that complement event-level investigations. It directly addresses the stated requirement.

B: Unblocking without correcting the compromised credentials or malicious behavior risks immediate re-abuse of the account. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Affected-device context helps scope remediation effort and identify whether critical or internet-exposed systems need accelerated treatment. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: The activity log supports rich filtering so analysts can isolate the user, application, object, location, or action associated with suspicious cloud behavior. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Advanced hunting supports flexible KQL queries across Defender XDR schema tables for proactive or investigation-driven searches. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T13-Q013: Use Microsoft Defender XDR reports for trend and coverage analysis – Defender XDR reports summarize security posture, activity, and trends in ways that complement event-level investigations.

Question 14

During a tenant review at Fabrikam Health, the service desk lead identifies one unresolved requirement. The next migration wave is blocked until the team can investigate the specific issue behind an unfavorable report trend. The design should minimize manual per-user administration where a scoped central control exists. The team will validate the change with 8 pilot groups before expanding it to 50 users. What should the administrator configure first?

  1. Mark the risky discovered app as unsanctioned and use supported enforcement integration where appropriate
  2. Drill from a Defender XDR report finding into the underlying security data
  3. Use Microsoft Security Exposure Management to investigate exposure paths and initiatives
  4. Create a Microsoft Defender for Office 365 alert policy
  5. Secure the compromised account before removing the sending restriction

Correct answer: B

Why: Reports identify patterns or issues; responders should use the related detailed records or incidents to determine the cause and required action. It directly addresses the stated requirement.

Option review:

A: Unsanctioning identifies disallowed apps and can integrate with supported controls to help restrict their use. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Reports identify patterns or issues; responders should use the related detailed records or incidents to determine the cause and required action. It directly addresses the stated requirement.

C: Security Exposure Management helps connect exposure signals into attack paths and initiatives, supporting risk-based prioritization beyond isolated findings. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Alert policies define the conditions and notification behavior for security events that should create administrator alerts. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Unblocking without correcting the compromised credentials or malicious behavior risks immediate re-abuse of the account. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T13-Q014: Drill from a Defender XDR report finding into the underlying security data – Reports identify patterns or issues; responders should use the related detailed records or incidents to determine the cause and required action.

Question 15

A quarterly control review at Margie Travel identifies a gap that must be corrected before the next audit. Security and operations teams agree on the target state: review recurring security patterns and operational trends across the environment. The design should minimize manual per-user administration where a scoped central control exists. The service desk has 67 related tickets from 21 business units, so the team wants a targeted fix. Which approach most directly addresses the requirement?

  1. Review simulation results to identify users or techniques that need additional training
  2. Prioritize the vulnerability recommendation with the highest risk and exposure impact
  3. Use Microsoft Defender XDR reports for trend and coverage analysis
  4. Create an activity policy in Defender for Cloud Apps with an alert
  5. Mark the risky discovered app as unsanctioned and use supported enforcement integration where appropriate

Correct answer: C

Why: Defender XDR reports summarize security posture, activity, and trends in ways that complement event-level investigations. It directly addresses the stated requirement.

Option review:

A: Simulation metrics show interaction patterns and training outcomes that can guide follow-up education and future campaign design. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Defender Vulnerability Management combines vulnerability, threat, exposure, and asset context to help prioritize remediation rather than ranking by CVE count alone. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Defender XDR reports summarize security posture, activity, and trends in ways that complement event-level investigations. It directly addresses the stated requirement.

D: Activity policies evaluate cloud activity criteria and can trigger alerts when matching events occur. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Unsanctioning identifies disallowed apps and can integrate with supported controls to help restrict their use. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T13-Q015: Use Microsoft Defender XDR reports for trend and coverage analysis – Defender XDR reports summarize security posture, activity, and trends in ways that complement event-level investigations.

Question 16

A quarterly control review at City Power & Light identifies a gap that must be corrected before the next audit. An internal assessment finds the control technically functional but unable to investigate the specific issue behind an unfavorable report trend. The service desk has 84 related tickets from 11 business units, so the team wants a targeted fix. The design should minimize manual per-user administration where a scoped central control exists. Which approach most directly addresses the requirement?

  1. Integrate Defender for Endpoint signals with Cloud App Discovery when endpoints are the chosen visibility source
  2. Correlate a suspicious indicator with Defender Threat Intelligence before blocking it broadly
  3. Configure a Safe Attachments policy
  4. Drill from a Defender XDR report finding into the underlying security data
  5. Review simulation results to identify users or techniques that need additional training

Correct answer: D

Why: Reports identify patterns or issues; responders should use the related detailed records or incidents to determine the cause and required action. It directly addresses the stated requirement.

Option review:

A: Defender for Endpoint integration can supply endpoint-based cloud app usage signals to Cloud App Discovery without requiring only perimeter firewall logs. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Threat-intelligence context can reduce false assumptions and reveal related infrastructure before a high-impact blocking decision is made. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Safe Attachments provides additional protection against unknown malicious attachments beyond signature-based malware detection. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Reports identify patterns or issues; responders should use the related detailed records or incidents to determine the cause and required action. It directly addresses the stated requirement.

E: Simulation metrics show interaction patterns and training outcomes that can guide follow-up education and future campaign design. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T13-Q016: Drill from a Defender XDR report finding into the underlying security data – Reports identify patterns or issues; responders should use the related detailed records or incidents to determine the cause and required action.

Question 17

Consolidated Messenger has completed a pilot and must now choose the production administration approach. Audit evidence shows that the current process cannot reliably review recurring security patterns and operational trends across the environment. The organization wants a reversible rollout with measurable verification before broad enforcement. The initial rollout covers 24 locations and approximately 100 managed identities or devices. Which action should the administrator take?

  1. Use quarantine and remediation actions for confirmed malicious messages
  2. Configure Defender for Endpoint settings in the Microsoft Defender portal
  3. Connect Microsoft 365 to Microsoft Defender for Cloud Apps with the app connector
  4. Integrate Defender for Endpoint signals with Cloud App Discovery when endpoints are the chosen visibility source
  5. Use Microsoft Defender XDR reports for trend and coverage analysis

Correct answer: E

Why: Defender XDR reports summarize security posture, activity, and trends in ways that complement event-level investigations. It directly addresses the stated requirement.

Option review:

A: Quarantine and message remediation actions remove or restrict access to malicious content without relying on users to delete messages manually. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Endpoint settings in the Defender portal govern service features and integrations rather than requiring per-device manual changes for every capability. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: The Microsoft 365 app connector supplies supported activity and governance integration to Defender for Cloud Apps. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Defender for Endpoint integration can supply endpoint-based cloud app usage signals to Cloud App Discovery without requiring only perimeter firewall logs. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Defender XDR reports summarize security posture, activity, and trends in ways that complement event-level investigations. It directly addresses the stated requirement.

Learning point: MS102-T13-Q017: Use Microsoft Defender XDR reports for trend and coverage analysis – Defender XDR reports summarize security posture, activity, and trends in ways that complement event-level investigations.

Question 18

Adventure Works has completed a pilot and must now choose the production administration approach. Administrators have confirmed the present design does not investigate the specific issue behind an unfavorable report trend. The affected scope contains 27 users across 14 administrative groups. Existing workload settings should remain unchanged unless the requirement specifically depends on them. Which administrative choice should be recommended?

  1. Drill from a Defender XDR report finding into the underlying security data
  2. Pivot from a suspicious activity-log event to the related user or app context
  3. Use Microsoft Defender XDR reports for trend and coverage analysis
  4. Use exposure initiatives to measure progress toward a defined security objective
  5. Use quarantine and remediation actions for confirmed malicious messages

Correct answer: A

Why: Reports identify patterns or issues; responders should use the related detailed records or incidents to determine the cause and required action. It directly addresses the stated requirement.

Option review:

A: Reports identify patterns or issues; responders should use the related detailed records or incidents to determine the cause and required action. It directly addresses the stated requirement.

B: Activity-log records are more useful when correlated with the involved user, app, IP, and adjacent events instead of reviewed as standalone lines. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Defender XDR reports summarize security posture, activity, and trends in ways that complement event-level investigations. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Exposure initiatives organize related recommendations around measurable security objectives, making them better suited than isolated alerts for posture improvement programs. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Quarantine and message remediation actions remove or restrict access to malicious content without relying on users to delete messages manually. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T13-Q018: Drill from a Defender XDR report finding into the underlying security data – Reports identify patterns or issues; responders should use the related detailed records or incidents to determine the cause and required action.

Question 19

The governance lead at Coho Winery is designing the next phase of the Microsoft 365 rollout. The support team has reproduced the issue and narrowed it to this requirement: review recurring security patterns and operational trends across the environment. The service desk has 44 related tickets from 4 business units, so the team wants a targeted fix. The administrator must avoid granting unrelated tenant-wide privilege. Which option best satisfies the requirement?

  1. Tune alert policy thresholds or recipients instead of weakening threat protection
  2. Use Microsoft Defender XDR reports for trend and coverage analysis
  3. Use the supported Defender for Endpoint onboarding method for the device-management platform
  4. Reassess the recommendation after remediation to verify exposure decreased
  5. Pivot from a suspicious activity-log event to the related user or app context

Correct answer: B

Why: Defender XDR reports summarize security posture, activity, and trends in ways that complement event-level investigations. It directly addresses the stated requirement.

Option review:

A: Alerting and threat protection are separate concerns; changing the alert policy can reduce notification noise without disabling the protection itself. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Defender XDR reports summarize security posture, activity, and trends in ways that complement event-level investigations. It directly addresses the stated requirement.

C: Defender for Endpoint provides multiple supported onboarding methods; choosing one aligned to the management platform improves consistency and verification. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Closing a change ticket is not proof of risk reduction; Defender Vulnerability Management should reflect improved exposure after telemetry updates. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Activity-log records are more useful when correlated with the involved user, app, IP, and adjacent events instead of reviewed as standalone lines. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T13-Q019: Use Microsoft Defender XDR reports for trend and coverage analysis – Defender XDR reports summarize security posture, activity, and trends in ways that complement event-level investigations.

Question 20

Datum Dynamics is migrating a business process to Microsoft 365 and wants the narrowest supported solution. The service owner wants a supportable design that will investigate the specific issue behind an unfavorable report trend. The response must address the cause described in the scenario rather than simply suppressing the symptom. The team will validate the change with 17 pilot groups before expanding it to 61 users. Which administrative choice should be recommended?

  1. Use an anomaly detection or app discovery policy when the requirement is behavior- or discovery-driven
  2. Investigate the incident in the Microsoft Defender portal
  3. Drill from a Defender XDR report finding into the underlying security data
  4. Prioritize remediation by exposure and business context rather than score alone
  5. Tune alert policy thresholds or recipients instead of weakening threat protection

Correct answer: C

Why: Reports identify patterns or issues; responders should use the related detailed records or incidents to determine the cause and required action. It directly addresses the stated requirement.

Option review:

A: Defender for Cloud Apps offers policy types tailored to activity anomalies and discovered-app governance scenarios. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Defender XDR incidents aggregate related alerts and evidence across supported products, giving responders a coordinated investigation view. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Reports identify patterns or issues; responders should use the related detailed records or incidents to determine the cause and required action. It directly addresses the stated requirement.

D: Secure Score is a posture indicator, not a complete risk model; exposure, asset criticality, and exploitability should inform remediation priority. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Alerting and threat protection are separate concerns; changing the alert policy can reduce notification noise without disabling the protection itself. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T13-Q020: Drill from a Defender XDR report finding into the underlying security data – Reports identify patterns or issues; responders should use the related detailed records or incidents to determine the cause and required action.

Question 21

City Power & Light has completed a pilot and must now choose the production administration approach. Audit evidence shows that the current process cannot reliably enrich an investigation with external threat intelligence about infrastructure, indicators, or adversary activity. The administrator must avoid granting unrelated tenant-wide privilege. The affected scope contains 78 users across 7 administrative groups. Which Microsoft 365 or Microsoft Entra capability is the best fit?

  1. Use preset security policies when a standardized Microsoft-recommended protection baseline meets the requirement
  2. Review the restricted entities page for the blocked user
  3. Create and track a remediation activity from the vulnerability recommendation
  4. Use Microsoft Defender Threat Intelligence for threat actor and indicator context
  5. Use an anomaly detection or app discovery policy when the requirement is behavior- or discovery-driven

Correct answer: D

Why: Defender Threat Intelligence provides intelligence context that helps analysts understand indicators and threat infrastructure beyond tenant telemetry alone. It directly addresses the stated requirement.

Option review:

A: Preset security policies bundle recommended configurations and can accelerate deployment of Standard or Strict protection baselines. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Restricted entities identifies users or other entities blocked because of suspicious or abusive sending behavior and supports controlled remediation. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Remediation workflows let security teams request, track, and validate vulnerability fixes instead of treating recommendations as a static report. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Defender Threat Intelligence provides intelligence context that helps analysts understand indicators and threat infrastructure beyond tenant telemetry alone. It directly addresses the stated requirement.

E: Defender for Cloud Apps offers policy types tailored to activity anomalies and discovered-app governance scenarios. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T13-Q021: Use Microsoft Defender Threat Intelligence for threat actor and indicator context – Defender Threat Intelligence provides intelligence context that helps analysts understand indicators and threat infrastructure beyond tenant telemetry alone.

Question 22

A quarterly control review at Alpine Ski House identifies a gap that must be corrected before the next audit. The existing configuration works for normal operations but fails the new requirement to validate threat context and relationships for an indicator found during an investigation. The administrator must avoid granting unrelated tenant-wide privilege. The initial rollout covers 20 locations and approximately 950 managed identities or devices. Which control should the team use?

  1. Validate the app connector status and granted permissions
  2. Review the discovered app risk score and usage before sanctioning or unsanctioning it
  3. Review Microsoft Secure Score improvement actions
  4. Use preset security policies when a standardized Microsoft-recommended protection baseline meets the requirement
  5. Correlate a suspicious indicator with Defender Threat Intelligence before blocking it broadly

Correct answer: E

Why: Threat-intelligence context can reduce false assumptions and reveal related infrastructure before a high-impact blocking decision is made. It directly addresses the stated requirement.

Option review:

A: A connector that is disabled, unhealthy, or missing required permissions can prevent expected activity from appearing. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Cloud App Discovery provides app risk information and usage context that should inform governance decisions instead of blocking solely because an app is unfamiliar. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Secure Score surfaces recommended security actions and scoring so administrators can prioritize improvements and track security posture progress. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Preset security policies bundle recommended configurations and can accelerate deployment of Standard or Strict protection baselines. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Threat-intelligence context can reduce false assumptions and reveal related infrastructure before a high-impact blocking decision is made. It directly addresses the stated requirement.

Learning point: MS102-T13-Q022: Correlate a suspicious indicator with Defender Threat Intelligence before blocking it broadly – Threat-intelligence context can reduce false assumptions and reveal related infrastructure before a high-impact blocking decision is made.

Question 23

The operations team at Contoso Retail needs to resolve an issue without granting broader permissions than necessary. Before the tenant expands to another business unit, the administrator must enrich an investigation with external threat intelligence about infrastructure, indicators, or adversary activity. The control owner requires a review after 21 days and evidence from 10 representative cases. Existing workload settings should remain unchanged unless the requirement specifically depends on them. Which Microsoft 365 or Microsoft Entra capability is the best fit?

  1. Use Microsoft Defender Threat Intelligence for threat actor and indicator context
  2. Configure a Safe Links policy
  3. Create an Attack Simulation Training campaign
  4. Use device groups or supported scoped settings when different endpoint populations require different treatment
  5. Validate the app connector status and granted permissions

Correct answer: A

Why: Defender Threat Intelligence provides intelligence context that helps analysts understand indicators and threat infrastructure beyond tenant telemetry alone. It directly addresses the stated requirement.

Option review:

A: Defender Threat Intelligence provides intelligence context that helps analysts understand indicators and threat infrastructure beyond tenant telemetry alone. It directly addresses the stated requirement.

B: Safe Links evaluates URLs and can block malicious destinations at click time, addressing link-based phishing threats. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Attack Simulation Training lets security teams run controlled simulations and associate training with the simulated attack experience. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Scoped endpoint administration helps align settings and response permissions to device populations and operational responsibilities. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: A connector that is disabled, unhealthy, or missing required permissions can prevent expected activity from appearing. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T13-Q023: Use Microsoft Defender Threat Intelligence for threat actor and indicator context – Defender Threat Intelligence provides intelligence context that helps analysts understand indicators and threat infrastructure beyond tenant telemetry alone.

Question 24

During a tenant review at Contoso Retail, the governance lead identifies one unresolved requirement. The administrator is comparing native Microsoft controls after documenting a requirement to validate threat context and relationships for an indicator found during an investigation. The affected scope contains 38 users across 23 administrative groups. The organization wants a reversible rollout with measurable verification before broad enforcement. What is the most appropriate next step?

  1. Use threat and exploit context when prioritizing two vulnerabilities with similar severity
  2. Correlate a suspicious indicator with Defender Threat Intelligence before blocking it broadly
  3. Use Cloud App Discovery data from supported endpoint or network traffic sources
  4. Drill from a Defender XDR report finding into the underlying security data
  5. Configure a Safe Links policy

Correct answer: B

Why: Threat-intelligence context can reduce false assumptions and reveal related infrastructure before a high-impact blocking decision is made. It directly addresses the stated requirement.

Option review:

A: Severity alone can be insufficient; active exploitation signals and organizational exposure provide stronger prioritization context. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Threat-intelligence context can reduce false assumptions and reveal related infrastructure before a high-impact blocking decision is made. It directly addresses the stated requirement.

C: Cloud App Discovery analyzes observed cloud traffic to identify applications and usage rather than relying only on an administrator-maintained application list. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Reports identify patterns or issues; responders should use the related detailed records or incidents to determine the cause and required action. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Safe Links evaluates URLs and can block malicious destinations at click time, addressing link-based phishing threats. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T13-Q024: Correlate a suspicious indicator with Defender Threat Intelligence before blocking it broadly – Threat-intelligence context can reduce false assumptions and reveal related infrastructure before a high-impact blocking decision is made.

Question 25

Trey Research is migrating a business process to Microsoft 365 and wants the narrowest supported solution. The support team has reproduced the issue and narrowed it to this requirement: enrich an investigation with external threat intelligence about infrastructure, indicators, or adversary activity. The affected scope contains 55 users across 13 administrative groups. Existing workload settings should remain unchanged unless the requirement specifically depends on them. What is the most appropriate next step?

  1. Assign and track improvement work from the Secure Score recommendation context
  2. Use Threat Explorer or Real-time detections to investigate the malicious message campaign
  3. Use Microsoft Defender Threat Intelligence for threat actor and indicator context
  4. Verify the device appears in Defender for Endpoint device inventory after onboarding
  5. Use threat and exploit context when prioritizing two vulnerabilities with similar severity

Correct answer: C

Why: Defender Threat Intelligence provides intelligence context that helps analysts understand indicators and threat infrastructure beyond tenant telemetry alone. It directly addresses the stated requirement.

Option review:

A: Secure Score recommendations provide context for remediation and progress tracking instead of requiring administrators to infer actions from raw alert counts. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Defender for Office 365 investigation tools provide message-level campaign and detection details needed to scope and respond to email threats. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Defender Threat Intelligence provides intelligence context that helps analysts understand indicators and threat infrastructure beyond tenant telemetry alone. It directly addresses the stated requirement.

D: Successful script execution alone does not prove service connectivity; device inventory and sensor health provide evidence that onboarding completed. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Severity alone can be insufficient; active exploitation signals and organizational exposure provide stronger prioritization context. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T13-Q025: Use Microsoft Defender Threat Intelligence for threat actor and indicator context – Defender Threat Intelligence provides intelligence context that helps analysts understand indicators and threat infrastructure beyond tenant telemetry alone.

Question 26

Trey Research has completed a pilot and must now choose the production administration approach. The support team has reproduced the issue and narrowed it to this requirement: validate threat context and relationships for an indicator found during an investigation. The team will validate the change with 3 pilot groups before expanding it to 72 users. The architecture board will reject a choice that solves a different problem from the one stated. Which control should the team use?

  1. Review exposed devices for the recommendation before scheduling the fix
  2. Filter the Defender for Cloud Apps activity log by user, IP address, activity, or application
  3. Use advanced hunting with KQL
  4. Correlate a suspicious indicator with Defender Threat Intelligence before blocking it broadly
  5. Assign and track improvement work from the Secure Score recommendation context

Correct answer: D

Why: Threat-intelligence context can reduce false assumptions and reveal related infrastructure before a high-impact blocking decision is made. It directly addresses the stated requirement.

Option review:

A: Affected-device context helps scope remediation effort and identify whether critical or internet-exposed systems need accelerated treatment. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: The activity log supports rich filtering so analysts can isolate the user, application, object, location, or action associated with suspicious cloud behavior. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Advanced hunting supports flexible KQL queries across Defender XDR schema tables for proactive or investigation-driven searches. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Threat-intelligence context can reduce false assumptions and reveal related infrastructure before a high-impact blocking decision is made. It directly addresses the stated requirement.

E: Secure Score recommendations provide context for remediation and progress tracking instead of requiring administrators to infer actions from raw alert counts. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T13-Q026: Correlate a suspicious indicator with Defender Threat Intelligence before blocking it broadly – Threat-intelligence context can reduce false assumptions and reveal related infrastructure before a high-impact blocking decision is made.

Question 27

Contoso Retail is standardizing administration after several teams used inconsistent procedures. The administrator is comparing native Microsoft controls after documenting a requirement to enrich an investigation with external threat intelligence about infrastructure, indicators, or adversary activity. The service desk has 89 related tickets from 16 business units, so the team wants a targeted fix. The response must address the cause described in the scenario rather than simply suppressing the symptom. Which Microsoft 365 or Microsoft Entra capability is the best fit?

  1. Use Microsoft Security Exposure Management to investigate exposure paths and initiatives
  2. Create a Microsoft Defender for Office 365 alert policy
  3. Secure the compromised account before removing the sending restriction
  4. Review exposed devices for the recommendation before scheduling the fix
  5. Use Microsoft Defender Threat Intelligence for threat actor and indicator context

Correct answer: E

Why: Defender Threat Intelligence provides intelligence context that helps analysts understand indicators and threat infrastructure beyond tenant telemetry alone. It directly addresses the stated requirement.

Option review:

A: Security Exposure Management helps connect exposure signals into attack paths and initiatives, supporting risk-based prioritization beyond isolated findings. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Alert policies define the conditions and notification behavior for security events that should create administrator alerts. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Unblocking without correcting the compromised credentials or malicious behavior risks immediate re-abuse of the account. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Affected-device context helps scope remediation effort and identify whether critical or internet-exposed systems need accelerated treatment. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Defender Threat Intelligence provides intelligence context that helps analysts understand indicators and threat infrastructure beyond tenant telemetry alone. It directly addresses the stated requirement.

Learning point: MS102-T13-Q027: Use Microsoft Defender Threat Intelligence for threat actor and indicator context – Defender Threat Intelligence provides intelligence context that helps analysts understand indicators and threat infrastructure beyond tenant telemetry alone.

Question 28

During a tenant review at Fourth Coffee, the governance lead identifies one unresolved requirement. The current workaround is too manual. The replacement should validate threat context and relationships for an indicator found during an investigation. The initial rollout covers 6 locations and approximately 150 managed identities or devices. The architecture board will reject a choice that solves a different problem from the one stated. What is the most appropriate next step?

  1. Correlate a suspicious indicator with Defender Threat Intelligence before blocking it broadly
  2. Prioritize the vulnerability recommendation with the highest risk and exposure impact
  3. Create an activity policy in Defender for Cloud Apps with an alert
  4. Mark the risky discovered app as unsanctioned and use supported enforcement integration where appropriate
  5. Use Microsoft Security Exposure Management to investigate exposure paths and initiatives

Correct answer: A

Why: Threat-intelligence context can reduce false assumptions and reveal related infrastructure before a high-impact blocking decision is made. It directly addresses the stated requirement.

Option review:

A: Threat-intelligence context can reduce false assumptions and reveal related infrastructure before a high-impact blocking decision is made. It directly addresses the stated requirement.

B: Defender Vulnerability Management combines vulnerability, threat, exposure, and asset context to help prioritize remediation rather than ranking by CVE count alone. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Activity policies evaluate cloud activity criteria and can trigger alerts when matching events occur. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Unsanctioning identifies disallowed apps and can integrate with supported controls to help restrict their use. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Security Exposure Management helps connect exposure signals into attack paths and initiatives, supporting risk-based prioritization beyond isolated findings. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T13-Q028: Correlate a suspicious indicator with Defender Threat Intelligence before blocking it broadly – Threat-intelligence context can reduce false assumptions and reveal related infrastructure before a high-impact blocking decision is made.

Question 29

During a tenant review at Adventure Works, the compliance administrator identifies one unresolved requirement. The support team has reproduced the issue and narrowed it to this requirement: enrich an investigation with external threat intelligence about infrastructure, indicators, or adversary activity. The initial rollout covers 19 locations and approximately 320 managed identities or devices. The architecture board will reject a choice that solves a different problem from the one stated. Which action should the administrator take?

  1. Correlate a suspicious indicator with Defender Threat Intelligence before blocking it broadly
  2. Use Microsoft Defender Threat Intelligence for threat actor and indicator context
  3. Configure a Safe Attachments policy
  4. Review simulation results to identify users or techniques that need additional training
  5. Prioritize the vulnerability recommendation with the highest risk and exposure impact

Correct answer: B

Why: Defender Threat Intelligence provides intelligence context that helps analysts understand indicators and threat infrastructure beyond tenant telemetry alone. It directly addresses the stated requirement.

Option review:

A: Threat-intelligence context can reduce false assumptions and reveal related infrastructure before a high-impact blocking decision is made. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Defender Threat Intelligence provides intelligence context that helps analysts understand indicators and threat infrastructure beyond tenant telemetry alone. It directly addresses the stated requirement.

C: Safe Attachments provides additional protection against unknown malicious attachments beyond signature-based malware detection. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Simulation metrics show interaction patterns and training outcomes that can guide follow-up education and future campaign design. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Defender Vulnerability Management combines vulnerability, threat, exposure, and asset context to help prioritize remediation rather than ranking by CVE count alone. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T13-Q029: Use Microsoft Defender Threat Intelligence for threat actor and indicator context – Defender Threat Intelligence provides intelligence context that helps analysts understand indicators and threat infrastructure beyond tenant telemetry alone.

Question 30

Alpine Ski House is troubleshooting a Microsoft 365 behavior that affects a limited but important user population. Audit evidence shows that the current process cannot reliably validate threat context and relationships for an indicator found during an investigation. The team wants evidence from the Microsoft 365 or Microsoft Entra control plane rather than assumptions. The control owner requires a review after 49 days and evidence from 9 representative cases. Which option best satisfies the requirement?

  1. Configure Defender for Endpoint settings in the Microsoft Defender portal
  2. Connect Microsoft 365 to Microsoft Defender for Cloud Apps with the app connector
  3. Correlate a suspicious indicator with Defender Threat Intelligence before blocking it broadly
  4. Integrate Defender for Endpoint signals with Cloud App Discovery when endpoints are the chosen visibility source
  5. Use Microsoft Defender Threat Intelligence for threat actor and indicator context

Correct answer: C

Why: Threat-intelligence context can reduce false assumptions and reveal related infrastructure before a high-impact blocking decision is made. It directly addresses the stated requirement.

Option review:

A: Endpoint settings in the Defender portal govern service features and integrations rather than requiring per-device manual changes for every capability. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: The Microsoft 365 app connector supplies supported activity and governance integration to Defender for Cloud Apps. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Threat-intelligence context can reduce false assumptions and reveal related infrastructure before a high-impact blocking decision is made. It directly addresses the stated requirement.

D: Defender for Endpoint integration can supply endpoint-based cloud app usage signals to Cloud App Discovery without requiring only perimeter firewall logs. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Defender Threat Intelligence provides intelligence context that helps analysts understand indicators and threat infrastructure beyond tenant telemetry alone. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T13-Q030: Correlate a suspicious indicator with Defender Threat Intelligence before blocking it broadly – Threat-intelligence context can reduce false assumptions and reveal related infrastructure before a high-impact blocking decision is made.

Popular posts

img