nerdexam
Microsoft

MS-102 · Question #585

You have a Microsoft 365 E5 subscription. You are implementing Microsoft Defender XDR. You need to ensure that you can view attack paths in Microsoft Security Exposure Management. What should you do…

The correct answer is C. Define critical assets. To view attack paths in Microsoft Security Exposure Management with E5 and Defender XDR, ensure all Microsoft 365 Defender workloads (Endpoint, Identity, Office 365, Cloud Apps) are active and onboarding data. Navigate to the Microsoft Defender portal > Exposure Management >…

Submitted by zhang_li· Apr 18, 2026Manage security and threats by using Microsoft Defender XDR

Question

You have a Microsoft 365 E5 subscription. You are implementing Microsoft Defender XDR. You need to ensure that you can view attack paths in Microsoft Security Exposure Management. What should you do first?

Options

  • AAdd an advanced hunting query.
  • BTag users, groups, and devices as sensitive.
  • CDefine critical assets.
  • DTag users and devices as honeytokens.

How the community answered

(20 responses)
  • A
    15% (3)
  • B
    5% (1)
  • C
    70% (14)
  • D
    10% (2)

Explanation

To view attack paths in Microsoft Security Exposure Management with E5 and Defender XDR, ensure all Microsoft 365 Defender workloads (Endpoint, Identity, Office 365, Cloud Apps) are active and onboarding data. Navigate to the Microsoft Defender portal > Exposure Management > Attack surface > Attack paths to visualize potential attacker pathways and critical asset risks. Steps to Ensure Attack Path Visibility: Verify Licensing and Onboarding: Confirm you have Microsoft 365 E5 or relevant security licenses. Ensure devices are onboarded to Defender for Endpoint and that cloud connectors (Defender for Cloud) are active to provide the necessary graph data. *-> Configure Critical Assets: Define your high-value assets within the Defender portal (Settings > Microsoft Defender XDR > Critical asset management). Exposure Management uses this to prioritize attack paths. Access the Attack Paths View: Sign in to the Microsoft Defender portal and navigate to Exposure Management > Attack surface > Attack paths. Analyze Data: Use the Overview tab to see top choke points and attack scenarios, or the Attack paths list for a detailed, filterable view. Permissions: Ensure you have the necessary roles assigned, such as "Security Administrator" or a custom role with permissions to access Exposure Management data. Attack paths are automatically generated by analyzing relationships across your hybrid environment, identifying how an attacker could move from an entry point to a critical asset. https://learn.microsoft.com/en-us/security-exposure-management/work-attack-paths-overview

Topics

#Microsoft Defender XDR#Security Exposure Management#attack paths#critical assets

Community Discussion

No community discussion yet for this question.

Full MS-102 Practice