MS-102 - Manage Security and Threats by Using Microsoft Defender XDR (28% of the exam) - Section 3.3

Implement and manage endpoint protection with Microsoft Defender for Endpoint.

Onboard devices to Microsoft Defender for Endpoint and configure endpoint detection and response, attack surface reduction rules, and vulnerability management. Understand how automated investigation reduces analyst workload by triaging and remediating common threats.

device onboardingendpoint detection and responseattack surface reductionvulnerability managementautomated investigation

Practice question for this objective

Free sampleManage Security and Threats by Using Microsoft Defender XDRmedium

You sign in to the Microsoft Defender portal as a Defender for Office 365-only customer. Why do you not see device protection features or the Defender for Endpoint device inventory in the portal?

  • AThe portal hides features for products you have not licensed and provisioned. Correct
  • BDevice protection requires a separate browser session at the Endpoint portal.
  • CDefender XDR has not been turned on for the tenant from the Settings page.
  • DThe Microsoft Entra ID role assigned is missing the Endpoint operator scope.
Apply the documented Microsoft 365 / Microsoft Entra ID behaviour to the scenario. In the Microsoft Defender portal customers see only the security features their subscription includes. With Defender for Office 365 but no Defender for Endpoint license, device protection features are not surfaced.

Why A is correct: Correct. In the Microsoft Defender portal customers see only the security features their subscription includes.

Why B is wrong: There is no separate Endpoint portal; the Defender portal at security.microsoft.com is the unified surface.

Why C is wrong: Turning on Defender XDR does not provision Defender for Endpoint; licensing is the gating factor.

Why D is wrong: Roles control access to surfaced features, not whether unlicensed product features appear at all.

See more MS-102 practice questions, answers explained.

Exam traps in Manage Security and Threats by Using Microsoft Defender XDR

Answers that look right on this material and are not. Each one is a distractor from a different question in the MS-102 bank for this domain.

  • Quarantine

    Why it is wrong: Quarantine is a Microsoft Defender Antivirus action on malicious files, not an ASR rule mode.

  • Group Policy deployment

    Why it is wrong: Group Policy is a Windows-only mechanism and cannot deploy onboarding packages to Linux.

  • Security Operator

    Why it is wrong: Security Operator allows acting on alerts and incidents; that exceeds read-only need.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.