Instiq
Chapter 3 · Manage security with Microsoft Defender XDR and Office 365·v1.0.0·Updated 6/29/2026·~14 min

What's changed: Created MS-102 Chapter 3 (domain: Defender XDR, part 1). Defender XDR investigate/respond (Security Exposure Management/Secure Score proactive posture, incidents = correlated alerts and triage, advanced hunting KQL, Defender Threat Intelligence) and Defender for Office 365 (threat policies anti-phishing/spam/malware, Safe Attachments detonation/Safe Links click-time re-evaluation, alert policies, Threat Explorer investigation, attack simulation training, restricted entities release).

3.1Investigate and respond with Defender XDR

Key points

Understand posture via Microsoft Security Exposure Management and Secure Score, triaging Defender XDR incidents and alerts, advanced hunting (KQL), and Microsoft Defender Threat Intelligence.

Security operations split into "improve posture proactively" and "detect and respond reactively". Microsoft Defender XDR unifies signals across multiple Defender products.

3.1.1Exposure management and Secure Score

Microsoft Security Exposure Management visualizes the org’s attack surface/exposure and attack paths to critical assets. Microsoft Secure Score scores recommended improvement actions to prioritize and raise posture. Both are proactive posture management—"reduce weaknesses before compromise"—a different layer from incident response.

3.1.2Incidents and alerts

A Defender XDR incident correlates multiple related alerts into one attack story. Analysts triage incidents, review scope (devices, users, mailboxes), and respond (approve automated remediation, isolate devices). Individual alerts are single detections; an incident is the higher-level grouping of them.

3.1.3Advanced hunting and Threat Intelligence

Advanced hunting uses KQL (Kusto Query Language) to proactively explore raw telemetry (devices, email, sign-ins) to find undetected threats and build custom detections. Microsoft Defender Threat Intelligence provides external threat info—threat actors, IOCs, threat analytics reports—to match observed indicators against known attacks. Advanced hunting = your own queries; Threat Intelligence = known threat information.

Exam point

Cues: "visualize attack surface/exposure and paths" = Exposure Management. "scored config improvements" = Secure Score. "correlated multi-alert response unit" = incident. "proactively hunt threats with KQL" = advanced hunting. "threat actors/IOCs/threat analytics" = Defender Threat Intelligence.

Warning

Watch the mix-ups: (1) Exposure Management/Secure Score (proactive posture) vs incidents/alerts (reactive detection/response). (2) An incident (correlated attack story) vs a single alert differ in granularity. (3) Advanced hunting (your own KQL queries) vs Threat Intelligence (provided threat info).

Diagram: proactive posture = Security Exposure Management (attack surface/exposure) and Secure Score (config improvement score); reactive response = incidents (correlate alerts into one attack and triage) and advanced hunting (proactive KQL); Microsoft Defender Threat Intelligence provides threat actors/IOCs/threat analytics.
Posture + response

3.1.4Section summary

  • Exposure Management = attack surface/exposure; Secure Score = scored improvements (proactive posture)
  • An incident correlates multiple alerts into one response unit; triage and respond
  • Advanced hunting = proactive KQL; Threat Intelligence = threat actors/IOCs/threat analytics

Sign in to track progress — Log in.

Quick check

(just a quick review)

Q1. Which unit correlates multiple related alerts into one attack so you can investigate/respond to the whole scope?

Q2. You want to write custom KQL queries over raw telemetry to proactively hunt undetected threats. Best?

Q3. Before any compromise, you want to prioritize config improvements and raise overall security posture. Best?

Q4. You want to match observed indicators (IPs, hashes) against known threat actors and threat analytics reports. Best?

Q5. You want to visualize the org’s attack surface and attack paths to critical assets to see where it’s exposed. Best?

Check your understandingPractice questions for Chapter 3: Manage security with Microsoft Defender XDR and Office 365