MS-102 - Manage Security and Threats by Using Microsoft Defender XDR (28% of the exam) - Section 3.1

Manage security reports and alerts using the Microsoft Defender portal.

Use the Microsoft Defender portal to review the incidents queue, threat analytics, and secure score to understand the current security posture of a tenant. Recognise how the action center surfaces pending and completed automated remediation actions.

Microsoft Defender portalsecure scoreincidents queuethreat analyticsaction center

Practice question for this objective

Free sampleManage Security and Threats by Using Microsoft Defender XDReasy

You manage 350 Windows 11 devices that are enrolled in Microsoft Intune. You need to onboard the devices to Microsoft Defender for Endpoint by using the method that scales best for managed devices. Which deployment method should you choose in the Microsoft Defender portal onboarding page?

  • ALocal script
  • BMicrosoft Intune / MDM Correct
  • CVDI onboarding scripts
  • DGroup Policy
Apply the documented Microsoft 365 / Microsoft Entra ID behaviour to the scenario. For Windows 10 and Windows 11 client devices that are already enrolled in Intune, the Microsoft Intune / Mobile Device Management option is the supported and scalable onboarding method.

Why A is wrong: The local script is officially limited to up to 10 devices and is intended for pilot or test scenarios only.

Why B is correct: Correct. For Windows 10 and Windows 11 client devices that are already enrolled in Intune, the Microsoft Intune / Mobile Device Management option is the supported and scalable onboarding method.

Why C is wrong: VDI scripts target non-persistent virtual desktop infrastructure devices, not standard managed laptops.

Why D is wrong: Group Policy works but Intune is the recommended scalable method for devices already managed by Intune.

See more MS-102 practice questions, answers explained.

Exam traps in Manage Security and Threats by Using Microsoft Defender XDR

Answers that look right on this material and are not. Each one is a distractor from a different question in the MS-102 bank for this domain.

  • Authentication Administrator

    Why it is wrong: Authentication Administrator manages user authentication methods (FIDO2 keys, MFA reset, password reset) but is not on the Secure Score write-access list; it cannot edit recommendation status.

  • Internal Cosmos DB telemetry from the analyst's own tenant.

    Why it is wrong: Tenant-internal Cosmos telemetry is not an input; Defender TI uses global Microsoft research data.

  • Mail flow rules in the Exchange admin center.

    Why it is wrong: Mail flow rules act on messages, not on alert visibility.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.