MS-102 Manage security and threats by using Microsoft Defender XDR • Set 3
MS-102 Manage security and threats by using Microsoft Defender XDR Practice Test 3 — 15 questions with explanations. Free, no signup.
A security analyst is investigating a potential attack where a user received a malicious email with an HTML attachment. The HTML file, when opened, fetched a JavaScript payload from a remote server that then dropped a binary on the user's machine and executed it. The analyst wants to create a custom detection rule in Microsoft 365 Defender Advanced Hunting that alerts when an email contains an HTML attachment with an external link, and that attachment is opened, causing a process creation. Which two tables should the analyst join in the KQL query to correlate the email attachment with the resulting process?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.