nerdexam
Microsoft

MS-102 · Question #55

You have a Microsoft 365 tenant that contains two users named User1 and User2. You create the alert policy shown in the following exhibit. User2 runs a script that modifies a file in a Microsoft…

The correct answer is A. 2. User2 modifies a file every 4 minutes for 2 hours, generating 30 total modification events (120 minutes ÷ 4 minutes = 30 events). However, the alert policy shown uses an aggregation window (typically 60 minutes) to group multiple matching activities into a single alert…

Submitted by tom_us· Apr 18, 2026Manage security and threats by using Microsoft Defender XDR

Question

You have a Microsoft 365 tenant that contains two users named User1 and User2. You create the alert policy shown in the following exhibit. User2 runs a script that modifies a file in a Microsoft SharePoint library once every four minutes and runs for a period of two hours. How many alerts will User1 receive?

Exhibit

MS-102 question #55 exhibit

Options

  • A2
  • B5
  • C10
  • D25
  • E30

How the community answered

(56 responses)
  • A
    77% (43)
  • B
    2% (1)
  • C
    11% (6)
  • D
    7% (4)
  • E
    4% (2)

Explanation

User2 modifies a file every 4 minutes for 2 hours, generating 30 total modification events (120 minutes ÷ 4 minutes = 30 events). However, the alert policy shown uses an aggregation window (typically 60 minutes) to group multiple matching activities into a single alert notification rather than firing one alert per event. With a 1-hour aggregation window, all events within the first hour are bundled into one alert, and all events within the second hour are bundled into a second alert. This produces exactly 2 alerts delivered to User1. This aggregation behavior is standard in Microsoft 365 alert policies to prevent alert fatigue from high-frequency events.

Topics

#Alert policies#Microsoft 365 security#Activity monitoring#SharePoint Online

Community Discussion

No community discussion yet for this question.

Full MS-102 Practice