MS-102 - Manage Security and Threats by Using Microsoft Defender XDR - Section 3.2

Implement and manage email and collaboration protection with Microsoft Defender for Office 365.

Configure Microsoft Defender for Office 365 policies including anti-phishing, Safe Links, and Safe Attachments to protect email and collaboration workloads. Use threat explorer and attack simulation training to investigate suspicious messages and measure user susceptibility.

anti-phishing policiesSafe LinksSafe Attachmentsattack simulation trainingthreat explorer

Practice question for this objective

Free sampleManage Security and Threats by Using Microsoft Defender XDRhard

Which signal sources can Microsoft Defender XDR correlate into a single incident in the Microsoft Defender portal? (Select 3 answers)

  • AEndpoint detection alerts generated by Microsoft Defender for Endpoint Correct
  • BIdentity attack alerts generated by Microsoft Defender for Identity Correct
  • CCloud app activity alerts from Microsoft Defender for Cloud Apps Correct
  • DDevice compliance state changes reported by Microsoft Intune
  • EMicrosoft Purview eDiscovery (Standard) case lifecycle events
XDR incident correlation pulls from the Defender product family (Endpoint, Identity, Cloud Apps, Office 365) plus Entra ID Protection and Defender for Cloud - not from Intune compliance or Purview Defender XDR correlates alerts from Microsoft Defender for Endpoint, Microsoft Defender for Identity, Microsoft Defender for Cloud Apps, Microsoft Defender for Office 365, Microsoft Entra ID Protection, and Microsoft Defender for Cloud into combined incidents in the Microsoft Defender portal.

Why A is correct: Correct. Endpoint detection alerts generated by Microsoft Defender for Endpoint is one of the keyed answers. Defender XDR correlates alerts from Microsoft Defender for Endpoint, Microsoft Defender for Identity, Microsoft Defender for Cloud Apps, Microsoft Defender for Office 365, Microsoft Entra ID Protection, and Microsoft Defender for Cloud into combined incidents in the Microsoft Defender portal.

Why B is correct: Correct. Identity attack alerts generated by Microsoft Defender for Identity is one of the keyed answers. Defender XDR correlates alerts from Microsoft Defender for Endpoint, Microsoft Defender for Identity, Microsoft Defender for Cloud Apps, Microsoft Defender for Office 365, Microsoft Entra ID Protection, and Microsoft Defender for Cloud into combined incidents in the Microsoft Defender portal.

Why C is correct: Correct. Cloud app activity alerts from Microsoft Defender for Cloud Apps is one of the keyed answers. Defender XDR correlates alerts from Microsoft Defender for Endpoint, Microsoft Defender for Identity, Microsoft Defender for Cloud Apps, Microsoft Defender for Office 365, Microsoft Entra ID Protection, and Microsoft Defender for Cloud into combined incidents in the Microsoft Defender portal.

Why D is wrong: Intune device compliance state changes feed Conditional Access and reporting, not Defender XDR incident correlation. Intune is a management plane, not a Defender signal source.

Why E is wrong: Purview eDiscovery (Standard) is a legal and investigation workload for content search and case management; its case events do not feed XDR incidents.

See more MS-102 practice questions, answers explained.

More in this domain

Back to all Manage Security and Threats by Using Microsoft Defender XDR objectives, or the MS-102 cert hub.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.