nerdexam
Microsoft

MS-102 · Question #117

You have a Microsoft 365 E5 subscription. You need to be alerted when Microsoft 365 Defender detects high-severity incidents. What should you use?

The correct answer is C. an alert policy. In the Microsoft 365 Defender portal, alert policies can be configured to trigger and send email notifications when incidents or alerts meeting specific criteria (such as high severity) are detected. Alert policies allow administrators to define thresholds, severity filters…

Submitted by salim_om· Apr 18, 2026Manage security and threats by using Microsoft Defender XDR

Question

You have a Microsoft 365 E5 subscription. You need to be alerted when Microsoft 365 Defender detects high-severity incidents. What should you use?

Options

  • Aa custom detection rule
  • Ba threat policy
  • Can alert policy
  • Da notification rule

How the community answered

(38 responses)
  • A
    3% (1)
  • B
    3% (1)
  • C
    89% (34)
  • D
    5% (2)

Explanation

In the Microsoft 365 Defender portal, alert policies can be configured to trigger and send email notifications when incidents or alerts meeting specific criteria (such as high severity) are detected. Alert policies allow administrators to define thresholds, severity filters, and notification recipients so they are promptly informed when Defender raises high-severity incidents. A custom detection rule creates alerts from advanced hunting queries. A threat policy configures protective actions (anti-phishing, anti-malware, etc.). A notification rule is a distractor in this context; alert policies are the correct mechanism for severity-based incident notifications.

Topics

#Microsoft 365 Defender#Alert Policies#Incident Management#Security Monitoring

Community Discussion

No community discussion yet for this question.

Full MS-102 Practice