nerdexam
Microsoft

MS-102 · Question #346

You have a Microsoft 365 E5 subscription. You need to be alerted when Microsoft Defender XDR detects high-severity incidents. What should you use?

The correct answer is C. a notification rule. In Microsoft Defender XDR, notification rules (also called alert notification rules or incident email notifications) are used to automatically send email alerts when incidents matching specified criteria - such as high severity - are detected. You configure these rules to…

Submitted by andreas_gr· Apr 18, 2026Manage security and threats by using Microsoft Defender XDR

Question

You have a Microsoft 365 E5 subscription. You need to be alerted when Microsoft Defender XDR detects high-severity incidents. What should you use?

Options

  • Aa custom detection rule
  • Ba threat policy
  • Ca notification rule

How the community answered

(38 responses)
  • A
    3% (1)
  • B
    3% (1)
  • C
    95% (36)

Explanation

In Microsoft Defender XDR, notification rules (also called alert notification rules or incident email notifications) are used to automatically send email alerts when incidents matching specified criteria - such as high severity - are detected. You configure these rules to specify recipients, severity filters, and other conditions. A custom detection rule (A) is used to proactively hunt for specific threats based on KQL queries and generate alerts, but is not the primary mechanism for incident severity notifications. A threat policy (B) is used for email threat protection configuration, not incident alerting.

Topics

#Microsoft Defender XDR#Incident Management#Alerting#Email Notifications

Community Discussion

No community discussion yet for this question.

Full MS-102 Practice