MS-102 - Manage Security and Threats by Using Microsoft Defender XDR (28% of the exam) - Section 3.2

Implement and manage email and collaboration protection with Microsoft Defender for Office 365.

Configure Microsoft Defender for Office 365 policies including anti-phishing, Safe Links, and Safe Attachments to protect email and collaboration workloads. Use threat explorer and attack simulation training to investigate suspicious messages and measure user susceptibility.

anti-phishing policiesSafe LinksSafe Attachmentsattack simulation trainingthreat explorer

Practice question for this objective

Free sampleManage Security and Threats by Using Microsoft Defender XDRhard

Which signal sources can Microsoft Defender XDR correlate into a single incident in the Microsoft Defender portal? (Select 3 answers)

  • AEndpoint detection alerts generated by Microsoft Defender for Endpoint Correct
  • BIdentity attack alerts generated by Microsoft Defender for Identity Correct
  • CCloud app activity alerts from Microsoft Defender for Cloud Apps Correct
  • DDevice compliance state changes reported by Microsoft Intune
  • EMicrosoft Purview eDiscovery (Standard) case lifecycle events
XDR incident correlation pulls from the Defender product family (Endpoint, Identity, Cloud Apps, Office 365) plus Entra ID Protection and Defender for Cloud - not from Intune compliance or Purview Defender XDR correlates alerts from Microsoft Defender for Endpoint, Microsoft Defender for Identity, Microsoft Defender for Cloud Apps, Microsoft Defender for Office 365, Microsoft Entra ID Protection, and Microsoft Defender for Cloud into combined incidents in the Microsoft Defender portal.

Why A is correct: Correct. Endpoint detection alerts generated by Microsoft Defender for Endpoint is one of the keyed answers. Defender XDR correlates alerts from Microsoft Defender for Endpoint, Microsoft Defender for Identity, Microsoft Defender for Cloud Apps, Microsoft Defender for Office 365, Microsoft Entra ID Protection, and Microsoft Defender for Cloud into combined incidents in the Microsoft Defender portal.

Why B is correct: Correct. Identity attack alerts generated by Microsoft Defender for Identity is one of the keyed answers. Defender XDR correlates alerts from Microsoft Defender for Endpoint, Microsoft Defender for Identity, Microsoft Defender for Cloud Apps, Microsoft Defender for Office 365, Microsoft Entra ID Protection, and Microsoft Defender for Cloud into combined incidents in the Microsoft Defender portal.

Why C is correct: Correct. Cloud app activity alerts from Microsoft Defender for Cloud Apps is one of the keyed answers. Defender XDR correlates alerts from Microsoft Defender for Endpoint, Microsoft Defender for Identity, Microsoft Defender for Cloud Apps, Microsoft Defender for Office 365, Microsoft Entra ID Protection, and Microsoft Defender for Cloud into combined incidents in the Microsoft Defender portal.

Why D is wrong: Intune device compliance state changes feed Conditional Access and reporting, not Defender XDR incident correlation. Intune is a management plane, not a Defender signal source.

Why E is wrong: Purview eDiscovery (Standard) is a legal and investigation workload for content search and case management; its case events do not feed XDR incidents.

See more MS-102 practice questions, answers explained.

Exam traps in Manage Security and Threats by Using Microsoft Defender XDR

Answers that look right on this material and are not. Each one is a distractor from a different question in the MS-102 bank for this domain.

  • No

    Why it is wrong: Built-in protection is enabled by default once Defender for Office 365 licensing is present, which is why coverage exists even when no admin-created policy exists.

  • URL rewriting inside RTF (TNEF) email messages.

    Why it is wrong: Safe Links does not provide protection for URLs in RTF/TNEF messages.

  • 50 users

    Why it is wrong: 50 is the cap for custom domains for domain impersonation, not users.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.