Guide 07 / 09 • Interview + practical learning

Microsoft 365 Defender / Defender XDR

40 representative questions, English and Roman Urdu explanations, examples, exercises and original visual diagrams.

Beginner + intermediate4–6 hours daily40 questions

← Pack index and combined learning plan

How to use this guide

Read the short answer first, then explain the example without reading. Complete the practice task and collect evidence. The 50/40/30/20-question counts follow twice the higher estimates in your table; they are a preparation target, not a guaranteed employer question bank.

Pehle short answer parho, phir example apni zubaan mein samjhao. Practice task complete karke evidence rakho. Answers ratta laganay ke bajaye steps aur reasoning samjho.

Lab requirements: Authorised test tenant or vendor-provided case study with appropriate security-product licences. Some email investigation and hunting features need additional plans. Use test mailboxes and safe supplied messages; do not send real phishing to other people.

Course outcomes / Aap kya kar saken ge

Beginner

  • Explain XDR products and coverage
  • Triage an incident and recognise email evidence
  • Distinguish delivery, click and compromise

XDR products aur coverage samjhao

Incident aur email evidence triage karo

Delivery, click aur compromise alag rakho

Intermediate

  • Scope a phishing campaign across identities and devices
  • Write cross-product hunting queries with valid keys
  • Investigate mailbox rules, consent and related sign-ins
  • Validate response actions and document account recovery

Phishing ka device aur identity scope investigate karo

Correct keys ke saath cross-product queries banao

Mailbox aur login evidence joro

Response aur recovery verify karo

Learning path and practice schedule

This is a suggested 100-hour topic plan: 28 beginner hours plus 72 additional intermediate hours. At 4–6 hours a day, allow approximately 5–7 study days for the beginner stage and 17–25 study days total for this guided course. These are planning estimates, not promises of independent workplace competence. Repeat stages if the practical checkpoints are weak. Related subjects overlap in the combined plan.

Daily routine: 4–6 hours

ActivityCore 4 hoursOptional extra 2 hours
Concepts and official tutorial60 minutes—
Hands-on lab or evidence exercise120 minutes90 minutes: a harder case or failed scenario
Interview answers aloud30 minutes30 minutes: mock interview and follow-ups
Review and evidence log30 minutes—

Roman Urdu: Roz aik ghanta concepts, do ghantay practical, aadha ghanta answers bol kar aur aadha ghanta review karo. Extra do ghantay hon to difficult lab aur mock interview karo. Har haftay chhay study days aur aik rest/catch-up day rakho.

Study time means focused work, excluding breaks. Allocate at least half to practical work. If no tenant or lab is available, analyse supplied data and diagrams, but record that limitation and revisit the task when you have access.

Stage and timeDirection and practiceResource / tutorialDeliverable in Roman Urdu
1. Beginner
8 hours
2–2 study days
Product coverage
Study XDR overview and inventory enabled products. Explain what unavailable licences or data mean for evidence coverage.
XDR overview and get started
Microsoft Defender XDR overview
Available products aur data gaps ki list banao.
2. Beginner
10 hours
2–3 study days
Incident triage
Examine a fictional multi-alert incident. Identify assets, timeline, relationships and business impact.
Defender portal guide
Defender XDR portal and investigation
Multi-alert incident ka timeline banao.
3. Beginner
10 hours
2–3 study days
Email investigation
Practise sender/authentication/message-ID analysis on safe supplied examples. Compare delivered, blocked, removed and clicked states.
Office 365 protection documentation
Defender for Office 365 documentation
Email states aur supporting evidence explain karo.
4. Intermediate
24 hours
4–6 study days
Cross-product hunting
Write queries using available EmailEvents, AlertInfo, AlertEvidence and endpoint tables. Explain joins, duplicates and time-window limitations.
Advanced hunting
Advanced hunting overview
Queries aur join limitations demonstrate karo.
5. Intermediate
24 hours
4–6 study days
Campaign response
Run a phishing and mailbox-compromise tabletop. Scope recipients, clicks, accounts and devices, then review verified response and recovery.
Response documentation
Defender XDR documentation: response and remediation
Campaign scope aur coordinated response report banao.
6. Intermediate
24 hours
4–6 study days
Capstone and interview
Produce an end-to-end incident report and explain competing hypotheses. Practise fifteen scenario answers with follow-up challenges.
Get started and investigation resources
Get started with Defender XDR
Report aur scenario mock interview complete karo.

Practical exit check

Beginner: Complete a basic task using documentation, explain the result and recognise when to escalate.

Intermediate: Complete a common scenario without a step-by-step answer, justify your checks, test an alternative explanation and verify the result. You may consult references as analysts do at work.

Beginner par documentation ke saath basic task karo. Intermediate par ready-made steps ke baghair scenario solve, reasoning explain aur result verify karo.

Visual explanations

Microsoft 365 Defender / Defender XDR concept and evidence mapEmail +collaborationEndpoint telemetryIdentity + cloudappsCorrelated incidentScoped response
Original concept diagram. The three inputs on the left contribute to the central investigation or assessment, supporting the decision on the right. Relationships are conceptual, not a screenshot or an exhaustive deployment architecture.

Left ki information central analysis mein use hoti hai, phir decision ya response support hota hai.

Microsoft 365 Defender / Defender XDR troubleshooting decision diagramYes / HaanNo / NahinUser clicked linkCheck follow-on evidenceCredentials or execution?Scope + containValidate + monitor
Example troubleshooting decision. Use the branch that matches the observed evidence; complete verification after any corrective action.

Evidence ke mutabiq Yes ya No branch choose karo. Action ke baad result verify karo.

40 interview questions

Level labels indicate study focus, not a formal certification standard. Each short answer is a starting point for a 30–60 second response; expand with the example and your own honest experience.

40 questions shown
  1. What is Microsoft 365 Defender called now?
  2. What does Defender XDR do?
  3. XDR versus SIEM: what is the difference?
  4. Which products contribute to Defender XDR?
  5. What is Defender for Office 365?
  6. What is an incident in Defender XDR?
  7. How do you prioritise the incident queue?
  8. What is an attack story?
  9. How do you investigate a reported phishing email?
  10. What message details matter in phishing triage?
  11. What are SPF, DKIM and DMARC?
  12. Why is a failed authentication result not enough to call an email malicious?
  13. What is Safe Links?
  14. What is Safe Attachments?
  15. What is quarantine used for?
  16. How do you check whether other users received the message?
  17. What is Threat Explorer used for?
  18. What is ZAP?
  19. A user clicked a phishing link. What next?
  20. How do you investigate suspicious inbox rules?
  21. What is business email compromise?
  22. How do you respond to a compromised mailbox?
  23. What is Defender for Identity?
  24. What is Defender for Cloud Apps?
  25. What is advanced hunting across products?
  26. How do you search EmailEvents?
  27. How do you investigate URL clicks?
  28. What is AlertInfo versus AlertEvidence?
  29. How do you correlate email and device events?
  30. What are custom detections?
  31. How do you handle legitimate administrative activity?
  32. What is automated investigation and remediation in XDR?
  33. What is automatic attack disruption?
  34. How do you review pending response actions?
  35. How do you scope a campaign?
  36. How do you use threat intelligence?
  37. How do you apply least privilege in the Defender portal?
  38. When do you escalate across teams?
  39. What does a good XDR closure record contain?
  40. How would you answer an end-to-end phishing scenario?
Beginner focus
Question 01 / 40

What is Microsoft 365 Defender called now?

Short interview answer · English

Microsoft Defender XDR.

Why this matters · English explanation

The earlier name remains common in job descriptions; explain the platform using current terminology.

Roman Urdu explanation
Microsoft 365 Defender ka current naam Defender XDR hai. Job adverts mein purana naam bhi milta hai.
Worked context / illustrative example
A recruiter asks about Microsoft 365 Defender and you describe cross-product investigation.
Your practical task
Explain both names without confusing it with antivirus.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Microsoft Defender XDR overview

Beginner focus
Question 02 / 40

What does Defender XDR do?

Short interview answer · English

It coordinates threat detection, investigation and response across supported security products.

Why this matters · English explanation

The available view depends on product licences, deployment and data coverage.

Roman Urdu explanation
XDR supported products ke alerts aur evidence jor kar investigation mein madad karta hai.
Worked context / illustrative example
Email, endpoint and identity activity are examined as one attack story.
Your practical task
Draw the relevant product contributions.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Microsoft Defender XDR overview

Beginner focus
Question 03 / 40

XDR versus SIEM: what is the difference?

Short interview answer · English

XDR correlates supported security-product signals; SIEM broadly analyses data from connected sources.

Why this matters · English explanation

They complement each other and can integrate rather than being mutually exclusive.

Roman Urdu explanation
XDR product signals jorta hai; SIEM broader connected logs analyse karta hai. Dono saath use ho sakte hain.
Worked context / illustrative example
Defender endpoint evidence is correlated with additional network logs in Sentinel.
Your practical task
Explain which data source each approach contributes.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Microsoft Defender XDR overview

Beginner focus
Question 04 / 40

Which products contribute to Defender XDR?

Short interview answer · English

Relevant products include Defender for Endpoint, Office 365, Identity and Cloud Apps.

Why this matters · English explanation

Not every tenant has every product enabled or every table populated.

Roman Urdu explanation
Endpoint, email, identity aur cloud apps products contribute kar saktay hain. Tenant coverage check karo.
Worked context / illustrative example
A tenant has endpoint data but no email hunting telemetry because the required product is absent.
Your practical task
Build a coverage checklist.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Microsoft Defender XDR overview

Beginner focus
Question 05 / 40

What is Defender for Office 365?

Short interview answer · English

Protection for supported email and collaboration workloads against threats such as phishing and malicious links.

Why this matters · English explanation

Feature availability varies by plan and configuration.

Roman Urdu explanation
Defender for Office 365 email aur collaboration threats protect karta hai. Plan aur settings check karo.
Worked context / illustrative example
A malicious message is detected and investigated with recipient information.
Your practical task
Explain email protection versus endpoint protection.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Defender for Office 365 documentation

Beginner focus
Question 06 / 40

What is an incident in Defender XDR?

Short interview answer · English

A correlated investigation case containing alerts, assets and evidence.

Why this matters · English explanation

Review connections critically and scope beyond the currently linked alerts if necessary.

Roman Urdu explanation
Incident related alerts aur evidence ka case hai. Current grouping poora scope guarantee nahin karti.
Worked context / illustrative example
A phishing alert and subsequent endpoint execution are correlated.
Your practical task
Summarise the attack story in four sentences.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Defender XDR portal and investigation

Beginner focus
Question 07 / 40

How do you prioritise the incident queue?

Short interview answer · English

Use severity, asset value, business impact, confidence and signs of active compromise.

Why this matters · English explanation

Priority may change as evidence reveals broader scope.

Roman Urdu explanation
Severity ke saath asset value aur active compromise ka evidence dekho.
Worked context / illustrative example
A lower-severity alert on a privileged identity receives urgent review.
Your practical task
Rank three incidents and justify the order.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Defender XDR portal and investigation

Beginner focus
Question 08 / 40

What is an attack story?

Short interview answer · English

A narrative linking events and affected assets to explain possible attacker progression.

Why this matters · English explanation

Correlation does not establish causation without supporting evidence.

Roman Urdu explanation
Attack story events ko sequence mein jorti hai. Related timing hamesha causation prove nahin karti.
Worked context / illustrative example
Message delivery, click, process execution and login are placed on a shared timeline.
Your practical task
Mark observed facts and inferred relationships separately.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Defender XDR portal and investigation

Intermediate focus
Question 09 / 40

How do you investigate a reported phishing email?

Short interview answer · English

Obtain message identifiers, sender and recipient details, inspect delivery and threat evidence, then scope clicks and downstream activity.

Why this matters · English explanation

Use approved analysis tools rather than opening unknown content normally.

Roman Urdu explanation
Message ID, sender, recipient aur delivery check karo. Unknown link normal browser mein mat kholo.
Worked context / illustrative example
A reported invoice message has a suspicious link and several recipients.
Your practical task
Draft a phishing triage checklist.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Defender for Office 365 documentation

Beginner focus
Question 10 / 40

What message details matter in phishing triage?

Short interview answer · English

Sender domains, authentication results, message IDs, URLs, attachments, recipients and delivery state.

Why this matters · English explanation

A display name is easily misleading and cannot establish origin.

Roman Urdu explanation
Display name par trust mat karo. Domain, authentication aur message identifiers dekho.
Worked context / illustrative example
The visible sender name resembles a manager but the domain differs.
Your practical task
Explain the difference between display name and sender domain.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Defender for Office 365 documentation

Beginner focus
Question 11 / 40

What are SPF, DKIM and DMARC?

Short interview answer · English

Email-domain authentication and policy mechanisms.

Why this matters · English explanation

Passing checks does not make all content safe; legitimate infrastructure or authenticated domains can still send malicious messages.

Roman Urdu explanation
SPF, DKIM aur DMARC email authentication controls hain. Pass ka matlab content safe nahin.
Worked context / illustrative example
An authenticated domain sends a phishing message with an attacker-controlled link.
Your practical task
Explain what each control assesses at a high level.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Defender for Office 365 documentation

Intermediate focus
Question 12 / 40

Why is a failed authentication result not enough to call an email malicious?

Short interview answer · English

Forwarding, configuration and legitimate sending arrangements can affect results.

Why this matters · English explanation

Combine authentication with content, infrastructure and behavioural evidence.

Roman Urdu explanation
Fail result ke saath forwarding aur configuration context bhi dekho. Akelay final verdict mat do.
Worked context / illustrative example
A legitimate forwarded message produces unexpected authentication details.
Your practical task
List corroborating evidence for a verdict.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Defender for Office 365 documentation

Beginner focus
Question 13 / 40

What is Safe Links?

Short interview answer · English

A feature providing supported URL protection and checks in covered workloads.

Why this matters · English explanation

Coverage, policies and user behaviour affect the result; it does not eliminate all phishing risk.

Roman Urdu explanation
Safe Links supported workloads mein URLs ki protection deta hai. Har phishing risk khatam nahin hota.
Worked context / illustrative example
A protected link is evaluated when accessed under the configured service behaviour.
Your practical task
Explain coverage and an investigation limitation.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Defender for Office 365 documentation

Beginner focus
Question 14 / 40

What is Safe Attachments?

Short interview answer · English

A feature providing additional analysis of attachments in covered workloads.

Why this matters · English explanation

Delivery behaviour and actions depend on the configured policy.

Roman Urdu explanation
Safe Attachments attachment analysis karta hai. Policy se delivery behaviour decide hota hai.
Worked context / illustrative example
A suspicious attachment is analysed before the configured delivery outcome.
Your practical task
Compare attachment analysis with a sender-authentication check.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Defender for Office 365 documentation

Beginner focus
Question 15 / 40

What is quarantine used for?

Short interview answer · English

Holding messages under configured protection policies and release permissions.

Why this matters · English explanation

Release must follow verification and delegated authority rather than user pressure alone.

Roman Urdu explanation
Quarantine suspicious message hold karti hai. Release se pehle verify aur authority check karo.
Worked context / illustrative example
A user requests release of a blocked message from an unknown sender.
Your practical task
Draft a release-review checklist.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Defender for Office 365 documentation

Beginner focus
Question 16 / 40

How do you check whether other users received the message?

Short interview answer · English

Use message identifiers, sender, URL or attachment evidence in available email investigation tools.

Why this matters · English explanation

Delivery, removal and access are separate states to verify.

Roman Urdu explanation
Same message ya indicators se doosray recipients dhoondo. Delivery aur removal alag states hain.
Worked context / illustrative example
A phishing campaign reached twelve mailboxes, but only some copies remain present.
Your practical task
Create a scope table with delivery and action state.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Defender for Office 365 documentation

Beginner focus
Question 17 / 40

What is Threat Explorer used for?

Short interview answer · English

Investigating email threats and relevant message activity where the feature is available.

Why this matters · English explanation

Use filters and message details to scope a campaign; availability depends on licensing.

Roman Urdu explanation
Threat Explorer email campaign investigate karta hai jab feature available ho. Filters aur message detail use karo.
Worked context / illustrative example
Filter a suspected campaign by sender and time window.
Your practical task
Explain required evidence before requesting removal.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Defender for Office 365 documentation

Beginner focus
Question 18 / 40

What is ZAP?

Short interview answer · English

Zero-hour auto purge provides post-delivery protection actions for supported messages and configurations.

Why this matters · English explanation

Confirm the actual action state; detection after delivery does not prove users never interacted.

Roman Urdu explanation
ZAP supported setup mein delivery ke baad protection action karta hai. User click pehle ho sakta hai.
Worked context / illustrative example
A message is removed after a later threat verdict.
Your practical task
Explain why click and endpoint investigation may still be needed.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Defender for Office 365 documentation

Beginner focus
Question 19 / 40

A user clicked a phishing link. What next?

Short interview answer · English

Establish what happened after the click, including credential entry, downloads, device activity and sign-ins.

Why this matters · English explanation

Use evidence to choose account and endpoint response actions.

Roman Urdu explanation
Click ke baad credentials, downloads aur sign-ins check karo. Response evidence ke mutabiq choose karo.
Worked context / illustrative example
A user entered credentials but did not download a file.
Your practical task
Compare response priorities for credential entry and file execution.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Defender XDR portal and investigation

Intermediate focus
Question 20 / 40

How do you investigate suspicious inbox rules?

Short interview answer · English

Review rule changes, actor, timing, forwarding destinations and related sign-ins.

Why this matters · English explanation

Legitimate rules exist, so verify intent and preserve evidence before changes.

Roman Urdu explanation
Inbox rules, actor aur destination check karo. Legitimate rule ko blindly remove mat karo.
Worked context / illustrative example
A new rule forwards sensitive messages to an unexpected destination.
Your practical task
Write an evidence-first investigation plan.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Defender for Office 365 documentation

Intermediate focus
Question 21 / 40

What is business email compromise?

Short interview answer · English

Abuse of trusted email identities or communication to induce fraudulent actions or access.

Why this matters · English explanation

It may involve account takeover or impersonation without malware.

Roman Urdu explanation
BEC trusted email ka misuse hai. Malware zaroori nahin; impersonation bhi ho sakti hai.
Worked context / illustrative example
A fake executive asks finance to change payment details.
Your practical task
List technical checks and business verification steps.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Defender for Office 365 documentation

Intermediate focus
Question 22 / 40

How do you respond to a compromised mailbox?

Short interview answer · English

Scope access and activity, preserve evidence, coordinate identity containment and review mail rules and malicious message spread.

Why this matters · English explanation

Validate recovery rather than stopping at password reset.

Roman Urdu explanation
Mailbox activity aur rules check karo; identity containment coordinate aur recovery verify karo.
Worked context / illustrative example
A mailbox sent suspicious messages to internal colleagues.
Your practical task
Draft a cross-team response checklist.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Defender XDR portal and investigation

Intermediate focus
Question 23 / 40

What is Defender for Identity?

Short interview answer · English

A product that detects and investigates relevant identity threats using supported identity telemetry.

Why this matters · English explanation

Understand deployment and coverage before assuming every domain event is visible.

Roman Urdu explanation
Defender for Identity identity threats detect karta hai. Deployment aur telemetry coverage confirm karo.
Worked context / illustrative example
Suspicious domain authentication activity becomes part of a wider investigation.
Your practical task
Explain how identity evidence complements endpoint evidence.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Microsoft Defender XDR overview

Intermediate focus
Question 24 / 40

What is Defender for Cloud Apps?

Short interview answer · English

A service supporting visibility and control over cloud-app activity and threats.

Why this matters · English explanation

Capabilities depend on connected applications, policies and licences.

Roman Urdu explanation
Cloud Apps service cloud activity aur threats par visibility deta hai. Connected apps aur licence check karo.
Worked context / illustrative example
An unusual cloud-app download pattern is investigated.
Your practical task
Identify one data-coverage dependency.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Microsoft Defender XDR overview

Intermediate focus
Question 25 / 40

What is advanced hunting across products?

Short interview answer · English

KQL-based investigation across available endpoint, identity, email and other tables.

Why this matters · English explanation

Use correct keys and time relationships; not all table schemas are interchangeable.

Roman Urdu explanation
Cross-product hunting available tables ko KQL se jorti hai. Matching key aur timing sahi rakho.
Worked context / illustrative example
Find whether an email recipient later had suspicious endpoint activity.
Your practical task
Sketch the required tables and matching identifiers.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Advanced hunting overview

Intermediate focus
Question 26 / 40

How do you search EmailEvents?

Short interview answer · English

Use relevant time, sender, recipient and delivery fields in an available populated table.

Why this matters · English explanation

A message event is not proof the user read or clicked it.

Roman Urdu explanation
EmailEvents delivery evidence deta hai; read ya click automatically prove nahin hota.
Worked context / illustrative example
EmailEvents
| where Timestamp > ago(24h)
| project Timestamp, SenderFromAddress, RecipientEmailAddress, Subject, DeliveryAction
Your practical task
Explain why access and product coverage matter.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Advanced hunting overview

Intermediate focus
Question 27 / 40

How do you investigate URL clicks?

Short interview answer · English

Use available click telemetry, message context and subsequent device or identity evidence.

Why this matters · English explanation

Interpret recorded action and coverage limitations rather than equating every click with compromise.

Roman Urdu explanation
URL click logs aur baad ki activity compare karo. Har click account compromise nahin.
Worked context / illustrative example
A recorded click leads to a blocked page and no further suspicious evidence.
Your practical task
Explain additional checks before closure.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Advanced hunting overview

Intermediate focus
Question 28 / 40

What is AlertInfo versus AlertEvidence?

Short interview answer · English

AlertInfo describes alerts; AlertEvidence provides related entities and evidence records.

Why this matters · English explanation

A join can produce multiple evidence rows per alert.

Roman Urdu explanation
AlertInfo alert details hai; AlertEvidence related evidence. Aik alert ki multiple rows ho sakti hain.
Worked context / illustrative example
Join on AlertId to inspect associated devices or accounts.
Your practical task
Explain why joined counts can overstate distinct alerts.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Advanced hunting overview

Intermediate focus
Question 29 / 40

How do you correlate email and device events?

Short interview answer · English

Use consistent user identities, message context and a justified time window.

Why this matters · English explanation

A shared timestamp or username alone may create misleading matches.

Roman Urdu explanation
Consistent identity aur justified time window use karo. Sirf same user se causation prove nahin.
Worked context / illustrative example
A recipient opens a suspicious attachment before an unusual process starts.
Your practical task
Explain alternative causes and additional validation.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Advanced hunting overview

Intermediate focus
Question 30 / 40

What are custom detections?

Short interview answer · English

Rules based on supported hunting logic that identify recurring suspicious activity.

Why this matters · English explanation

Required fields, scheduling and response options depend on the detection configuration.

Roman Urdu explanation
Custom detection hunting logic se recurring threat detect karti hai. Required fields aur schedule check karo.
Worked context / illustrative example
A tested query is adapted into a supported custom detection.
Your practical task
Define coverage and false-positive acceptance criteria.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Advanced hunting overview

Intermediate focus
Question 31 / 40

How do you handle legitimate administrative activity?

Short interview answer · English

Validate actor, approved change, timing and expected behaviour, then classify and tune narrowly if appropriate.

Why this matters · English explanation

Authorisation evidence should match the observed action.

Roman Urdu explanation
Actor aur approved change ko actual action se match karo. Legitimate confirm ho to narrow tuning karo.
Worked context / illustrative example
An approved script launches during scheduled endpoint maintenance.
Your practical task
Write an evidence-backed classification note.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Defender XDR portal and investigation

Intermediate focus
Question 32 / 40

What is automated investigation and remediation in XDR?

Short interview answer · English

Supported automation that analyses evidence and carries out or proposes remediation.

Why this matters · English explanation

Monitor action status and approval boundaries; cross-product scope requires validation.

Roman Urdu explanation
Automation evidence analyse aur remediation propose ya execute karti hai. Action state aur approvals verify karo.
Worked context / illustrative example
One artefact is remediated while another response awaits approval.
Your practical task
Explain why an incident can remain open after one action succeeds.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Defender XDR documentation: response and remediation

Intermediate focus
Question 33 / 40

What is automatic attack disruption?

Short interview answer · English

A capability that uses supported high-confidence signals to interrupt active attacks.

Why this matters · English explanation

Prerequisites and product coverage matter, and analysts still need to review scope and recovery.

Roman Urdu explanation
Attack disruption active attack ko interrupt karne mein madad karti hai. Investigation aur recovery phir bhi zaroori hain.
Worked context / illustrative example
An automatic action limits an account or device during a detected attack.
Your practical task
Describe post-action review and release criteria.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Defender XDR documentation: response and remediation

Intermediate focus
Question 34 / 40

How do you review pending response actions?

Short interview answer · English

Check supporting evidence, target, impact, permissions and the proposed action before approval.

Why this matters · English explanation

Then verify execution and retain an audit trail.

Roman Urdu explanation
Approve se pehle evidence aur target check karo. Baad mein execution verify karo.
Worked context / illustrative example
A pending action targets a production asset with significant business impact.
Your practical task
Create an approval review checklist.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Defender XDR documentation: response and remediation

Intermediate focus
Question 35 / 40

How do you scope a campaign?

Short interview answer · English

Search shared indicators and behaviours across recipients, devices and accounts over an appropriate period.

Why this matters · English explanation

Record coverage gaps and distinguish attempted targeting from confirmed impact.

Roman Urdu explanation
Indicators se recipients, devices aur accounts ka scope nikalo. Targeting aur confirmed impact alag hain.
Worked context / illustrative example
Fifty recipients were targeted, five clicked and one device executed suspicious code.
Your practical task
Build a targeting-to-impact summary.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Defender XDR portal and investigation

Intermediate focus
Question 36 / 40

How do you use threat intelligence?

Short interview answer · English

Use it to add context and prioritise hypotheses, then validate against observed local activity.

Why this matters · English explanation

A report or reputation label is not sufficient evidence of compromise.

Roman Urdu explanation
Threat intel context hai. Local logs se validate karo, sirf label se decision mat lo.
Worked context / illustrative example
A reported malicious domain appears in a blocked connection with no execution evidence.
Your practical task
State a justified conclusion and limitation.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Advanced hunting overview

Intermediate focus
Question 37 / 40

How do you apply least privilege in the Defender portal?

Short interview answer · English

Assign appropriate investigation and response permissions for the available security workload.

Why this matters · English explanation

Effective access depends on the configured role model and scope.

Roman Urdu explanation
Investigate aur response ke roles task ke mutabiq do. Actual role model aur scope verify karo.
Worked context / illustrative example
An analyst can read evidence while another authorised role approves sensitive actions.
Your practical task
Create a read-versus-response access matrix.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Microsoft Defender XDR overview

Intermediate focus
Question 38 / 40

When do you escalate across teams?

Short interview answer · English

When identity, endpoint, email or business actions need another team's ownership or authority.

Why this matters · English explanation

Send a clear evidence package and keep incident coordination intact.

Roman Urdu explanation
Doosri team ki authority ya expertise chahiye ho to clear evidence ke saath escalate karo.
Worked context / illustrative example
An email compromise requires identity containment and finance verification.
Your practical task
Write a coordinated escalation with named functional owners.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Defender XDR portal and investigation

Intermediate focus
Question 39 / 40

What does a good XDR closure record contain?

Short interview answer · English

Attack hypothesis, confirmed scope, evidence, verified response, classification and remaining follow-up.

Why this matters · English explanation

Do not confuse removal of one message with complete account recovery.

Roman Urdu explanation
Closure mein scope, evidence aur verified actions likho. Aik email remove hona full recovery nahin.
Worked context / illustrative example
A campaign is closed after email, endpoint and identity checks are completed.
Your practical task
Draft a closure note with residual risks.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Defender XDR portal and investigation

Intermediate focus
Question 40 / 40

How would you answer an end-to-end phishing scenario?

Short interview answer · English

Explain intake, message analysis, recipient scope, click and execution checks, containment, validation and reporting.

Why this matters · English explanation

Use a real or clearly labelled lab example and state what you personally did.

Roman Urdu explanation
Intake se report tak sequence clear batao. Lab ko lab aur apna actual role clear rakho.
Worked context / illustrative example
A simulated phishing investigation links message evidence to a suspicious sign-in and documented response plan.
Your practical task
Deliver a three-minute answer and handle two follow-ups.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Get started with Defender XDR

Quick revision sheet

Cover the answers and explain each question aloud. For scenarios use: Trigger → Evidence → Checks → Decision → Verification → Documentation.

Scenario answer mein trigger, evidence, checks, decision, verification aur documentation clear batao.

QuestionAnswer prompt
1. What is Microsoft 365 Defender called now?Microsoft Defender XDR.
2. What does Defender XDR do?It coordinates threat detection, investigation and response across supported security products.
3. XDR versus SIEM: what is the difference?XDR correlates supported security-product signals; SIEM broadly analyses data from connected sources.
4. Which products contribute to Defender XDR?Relevant products include Defender for Endpoint, Office 365, Identity and Cloud Apps.
5. What is Defender for Office 365?Protection for supported email and collaboration workloads against threats such as phishing and malicious links.
6. What is an incident in Defender XDR?A correlated investigation case containing alerts, assets and evidence.
7. How do you prioritise the incident queue?Use severity, asset value, business impact, confidence and signs of active compromise.
8. What is an attack story?A narrative linking events and affected assets to explain possible attacker progression.
9. How do you investigate a reported phishing email?Obtain message identifiers, sender and recipient details, inspect delivery and threat evidence, then scope clicks and downstream activity.
10. What message details matter in phishing triage?Sender domains, authentication results, message IDs, URLs, attachments, recipients and delivery state.
11. What are SPF, DKIM and DMARC?Email-domain authentication and policy mechanisms.
12. Why is a failed authentication result not enough to call an email malicious?Forwarding, configuration and legitimate sending arrangements can affect results.
13. What is Safe Links?A feature providing supported URL protection and checks in covered workloads.
14. What is Safe Attachments?A feature providing additional analysis of attachments in covered workloads.
15. What is quarantine used for?Holding messages under configured protection policies and release permissions.
16. How do you check whether other users received the message?Use message identifiers, sender, URL or attachment evidence in available email investigation tools.
17. What is Threat Explorer used for?Investigating email threats and relevant message activity where the feature is available.
18. What is ZAP?Zero-hour auto purge provides post-delivery protection actions for supported messages and configurations.
19. A user clicked a phishing link. What next?Establish what happened after the click, including credential entry, downloads, device activity and sign-ins.
20. How do you investigate suspicious inbox rules?Review rule changes, actor, timing, forwarding destinations and related sign-ins.
21. What is business email compromise?Abuse of trusted email identities or communication to induce fraudulent actions or access.
22. How do you respond to a compromised mailbox?Scope access and activity, preserve evidence, coordinate identity containment and review mail rules and malicious message spread.
23. What is Defender for Identity?A product that detects and investigates relevant identity threats using supported identity telemetry.
24. What is Defender for Cloud Apps?A service supporting visibility and control over cloud-app activity and threats.
25. What is advanced hunting across products?KQL-based investigation across available endpoint, identity, email and other tables.
26. How do you search EmailEvents?Use relevant time, sender, recipient and delivery fields in an available populated table.
27. How do you investigate URL clicks?Use available click telemetry, message context and subsequent device or identity evidence.
28. What is AlertInfo versus AlertEvidence?AlertInfo describes alerts; AlertEvidence provides related entities and evidence records.
29. How do you correlate email and device events?Use consistent user identities, message context and a justified time window.
30. What are custom detections?Rules based on supported hunting logic that identify recurring suspicious activity.
31. How do you handle legitimate administrative activity?Validate actor, approved change, timing and expected behaviour, then classify and tune narrowly if appropriate.
32. What is automated investigation and remediation in XDR?Supported automation that analyses evidence and carries out or proposes remediation.
33. What is automatic attack disruption?A capability that uses supported high-confidence signals to interrupt active attacks.
34. How do you review pending response actions?Check supporting evidence, target, impact, permissions and the proposed action before approval.
35. How do you scope a campaign?Search shared indicators and behaviours across recipients, devices and accounts over an appropriate period.
36. How do you use threat intelligence?Use it to add context and prioritise hypotheses, then validate against observed local activity.
37. How do you apply least privilege in the Defender portal?Assign appropriate investigation and response permissions for the available security workload.
38. When do you escalate across teams?When identity, endpoint, email or business actions need another team's ownership or authority.
39. What does a good XDR closure record contain?Attack hypothesis, confirmed scope, evidence, verified response, classification and remaining follow-up.
40. How would you answer an end-to-end phishing scenario?Explain intake, message analysis, recipient scope, click and execution checks, containment, validation and reporting.

Capstone and assessment

Investigate a simulated phishing campaign with one suspicious sign-in and one endpoint event. Separate targeting from confirmed impact; submit scope, queries and validated response recommendations.

Capstone mein evidence, reasoning aur verified result do. Jo cheez available nahin us ki limitation likho. Lab work ko production experience keh kar present mat karo.

AreaSelf-assessment target
Evidence and technical accuracyAll key claims supported by relevant records, outputs or diagrams
Investigation reasoningAt least one alternative explanation tested; gaps clearly identified
Practical deliveryTask outcome verified, including one negative or failure test
CommunicationExplain the case in two minutes and answer two unprepared follow-ups

This is a study assessment, not a vendor certification or guarantee of interview success. Repeat the task if you cannot explain why your checks were necessary.

Official references and tutorials

References provide deeper detail. Some pages are broad documentation hubs: navigate to the relevant feature and check current licensing, platform support and permissions. Guidance is paraphrased; diagrams and fictional examples are original study material.