MS-102 Manage security and threats by using Microsoft Defender XDR • Set 2
MS-102 Manage security and threats by using Microsoft Defender XDR Practice Test 2 — 15 questions with explanations. Free, no signup.
A security analyst wants to create a custom detection rule in Microsoft Defender XDR that triggers when a user receives a phishing email (delivered to inbox) and then, from their Windows device, establishes a network connection to a known malicious IP address. The rule will be based on an advanced hunting query. Which two tables should the analyst join in the KQL query to capture both the email delivery event and the network connection event?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.