nerdexam
Microsoft

MS-102 · Question #378

You have a Microsoft 365 E5 subscription that uses Microsoft Defender for Endpoint and Microsoft Intune. All devices run Windows 11 and are Microsoft Entra joined. You are alerted to a zero-day…

The correct answer is A. From Threat analytics, view the list of vulnerable devices. D. Select the affected devices and request remediation. To identify devices affected by a zero-day attack and request remediation, use Threat analytics to view vulnerable devices and then initiate remediation requests through the Defender portal.

Submitted by jaden.t· Apr 18, 2026Manage security and threats by using Microsoft Defender XDR

Question

You have a Microsoft 365 E5 subscription that uses Microsoft Defender for Endpoint and Microsoft Intune. All devices run Windows 11 and are Microsoft Entra joined. You are alerted to a zero-day attack. You need to identify which devices were affected by the attack and send a request to Intune administrators to update the affected devices. Which two actions should you perform in the Microsoft Defender portal? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

Options

  • AFrom Threat analytics, view the list of vulnerable devices.
  • BFrom Incidents & alerts, select the latest incident.
  • CFrom Vulnerability management, open the security recommendation.
  • DSelect the affected devices and request remediation.

How the community answered

(43 responses)
  • A
    84% (36)
  • B
    12% (5)
  • C
    5% (2)

Why each option

To identify devices affected by a zero-day attack and request remediation, use Threat analytics to view vulnerable devices and then initiate remediation requests through the Defender portal.

AFrom Threat analytics, view the list of vulnerable devices.Correct

Threat analytics in Microsoft Defender XDR provides detailed reports on active threats, including zero-day attacks, and specifically lists devices in the organization that are exposed to or affected by the specific threat.

BFrom Incidents & alerts, select the latest incident.

While incidents provide alerts, Threat analytics offers a more consolidated and comprehensive view of the overall impact and affected devices for an organizational threat campaign like a zero-day attack.

CFrom Vulnerability management, open the security recommendation.

Vulnerability management focuses on proactively identifying and addressing software and configuration weaknesses rather than reactively identifying devices actively impacted by a specific zero-day attack.

DSelect the affected devices and request remediation.Correct

After identifying the affected devices, the Microsoft Defender portal allows selection of those devices to initiate a remediation request, which integrates with Microsoft Intune for deployment by administrators.

Concept tested: Identifying affected devices and initiating remediation for zero-day threats

Source: https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/threat-analytics?view=o365-worldwide

Topics

#Threat analytics#Zero-day attack#Vulnerable devices#Device remediation

Community Discussion

No community discussion yet for this question.

Full MS-102 Practice