nerdexam
Microsoft

MS-102 · Question #378

You have a Microsoft 365 E5 subscription that uses Microsoft Defender for Endpoint and Microsoft Intune. All devices run Windows 11 and are Microsoft Entra joined. You are alerted to a zero-day attack

Sign in or unlock MS-102 to reveal the answer and full explanation for question #378. The question stem and answer options stay visible for context.

Submitted by jaden.t· Apr 18, 2026Manage security and threats by using Microsoft Defender XDR

Question

You have a Microsoft 365 E5 subscription that uses Microsoft Defender for Endpoint and Microsoft Intune. All devices run Windows 11 and are Microsoft Entra joined. You are alerted to a zero-day attack. You need to identify which devices were affected by the attack and send a request to Intune administrators to update the affected devices. Which two actions should you perform in the Microsoft Defender portal? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

Options

  • AFrom Threat analytics, view the list of vulnerable devices.
  • BFrom Incidents & alerts, select the latest incident.
  • CFrom Vulnerability management, open the security recommendation.
  • DSelect the affected devices and request remediation.

Unlock MS-102 to see the answer

You've previewed enough free MS-102 questions. Unlock MS-102 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#Threat analytics#Zero-day attack#Vulnerable devices#Device remediation
Full MS-102 Practice