How to generate a Defender for Endpoint alert for malicious device activity?

Implement and manage endpoint protection by using Microsoft Defender for Endpoint
Answer Correct answer: D — From the Microsoft Defender portal, create an Advanced hunting query and a detection rule.

You have a Microsoft 365 subscription that uses Microsoft Defender for Endpoint. All the devices in your organization are onboarded to Microsoft Defender for Endpoint. You need to ensure that an alert is generated if malicious activity was detected on a device during the last 24 hours. What should you do?

  1. From the Microsoft Purview compliance portal, create a data loss prevention (DLP) policy.
  2. From the Microsoft Defender portal, create an alert suppression rule and assign an alert.
  3. From Advanced hunting, create a query and a detection rule.
  4. From the Microsoft Defender portal, create an Advanced hunting query and a detection rule. Correct Answer

Community Votes

D
100%

100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

It tests the Defender for Endpoint custom detection workflow, and the trap is choosing option C when it describes the same Advanced hunting action but omits the explicit Microsoft Defender portal context that makes D the best answer.

This MS-102 question asks how to ensure an alert is generated in Microsoft Defender for Endpoint when malicious activity is detected on a device during the last 24 hours. The page establishes that the correct answer is to create an Advanced hunting query and a detection rule from the Microsoft Defender portal (D).

The most common mistake is picking option C because it mentions Advanced hunting, but D is the better answer since it correctly places the Advanced hunting query and detection rule inside the Microsoft Defender portal, which is the documented management path.

Community Discussion (3 comments)

makonmakon 👍 7 Selected: D
Looks like C and D are the same answers but D provides complete explanation.
sVn01 👍 1 Selected: D
D is correct, i think because its 'From the Defender Portal' instead of answer C.
SeijuroSGD 👍 1
The correct answer is: C D. Microsoft Defender portal (Advanced hunting query and detection rule) – This is almost correct, but Advanced hunting is inside Microsoft Defender, so this is redundant. The correct way is via Advanced hunting > Detection rule (option C).

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Creating a custom detection rule is the documented way to generate an alert when an Advanced hunting query finds specific activity, such as malicious device activity in the last 24 hours. Option D correctly states that this is done from the Microsoft Defender portal by creating an Advanced hunting query and a detection rule. The Microsoft Defender portal is the management console for Defender for Endpoint, and Advanced hunting > Detection rules is the exact path for custom detections. Because the question asks for the action that ensures an alert, D matches the official workflow and is the best single answer.

Why the Other Options Are Wrong

Option A is wrong because a Microsoft Purview DLP policy controls data handling and exfiltration, not endpoint malicious-activity alerts. Option B is wrong because an alert suppression rule silences or hides matching alerts; it does not create a new alert for detected malicious activity. Option C describes essentially the same Advanced hunting detection-rule workflow as D, but it omits the Microsoft Defender portal context that the exam expects; because MS-102 questions often require the most complete and correctly scoped answer, D is preferred over C. If C and D appear identical, D is the fuller and more precise option.

Community Comment Notes

Commenters noticed the near-duplicate options. makonmakon wrote that "C and D are the same answers but D provides complete explanation" and selected D. sVn01 also chose D, reasoning that it says "From the Defender Portal" instead of just Advanced hunting. SeijuroSGD argued that "Advanced hunting is inside Microsoft Defender", making the portal reference redundant and possibly favoring C, but on a single-best-answer exam the explicit portal path and complete workflow in D is the safer choice.

Official Reference

Exam Strategy

When two options describe the same workflow, choose the one with the correct scope and complete path—here, the Microsoft Defender portal is the authoritative place for Advanced hunting and custom detection rules. On MS-102, avoid overthinking; pick the option that explicitly matches the portal and feature name in official documentation.

Frequently Asked Questions

Why is option C wrong if it also uses Advanced hunting?

C is not factually wrong, but D is the better answer because it fully specifies the Microsoft Defender portal and matches Microsoft's documented path for custom detection rules.

Can a DLP policy or alert suppression rule generate the required alert?

No. A Purview DLP policy governs data handling, and an alert suppression rule hides matching alerts; neither creates a new Defender for Endpoint alert for malicious device activity.

Related Analysis

Practice All MS-102 Questions

Access 111 questions with complete answers and detailed explanations.

View Full MS-102 Practice Test →

← Back to MS-102 Study Guide