MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
A security analyst is using Microsoft 365 Defender Advanced Hunting to investigate a potential malware outbreak. The analyst needs to find all devices where a specific signed executable (known to be malicious) was created in the past 24 hours. Which Advanced Hunting table should be queried to detect the creation of the executable file?
⚠ Common exam trap
Candidates often confuse file creation with process execution, mistakenly selecting DeviceProcessEvents because they think of the executable running, but the question explicitly asks for the creation event, which is only captured in DeviceFileEvents.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DeviceFileEvents
The DeviceFileEvents table in Microsoft 365 Defender Advanced Hunting captures file creation, modification, and deletion events. Since the question specifically asks for detecting the creation of a signed executable file, this table provides the necessary data, including file name, path, and timestamp, to identify when and where the malicious executable was created.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
DeviceFileEvents
Why this is correct
DeviceFileEvents is the correct table in Microsoft 365 Defender's advanced hunting schema for this scenario because it records file creation, modification, rename, and deletion events. Its columns include FileName, FolderPath, and Timestamp, allowing you to search for the malicious executable by its exact name and location on disk. Process, network, and registry tables do not provide this file-system telemetry.
- ✗
DeviceProcessEvents
Why it's wrong here
DeviceProcessEvents captures process creation and execution events, such as ProcessName, ProcessCommandLine, and parent/child relationships. While a malicious executable might eventually appear in this table when it runs, the question asks about finding the executable's file creation, which happens before execution. Relying on this table would miss droppers that create files but are never executed, and even when a process is recorded, the file's creation timestamp and full folder path may not be captured.
- ✗
DeviceNetworkEvents
Why it's wrong here
DeviceNetworkEvents is incorrect because it tracks outbound and inbound network connections, including SourceIP, DestinationIP, Ports, and URLs. It does not contain a FileName or FolderPath field, so it cannot be used to identify the malicious executable on disk. Network telemetry is useful for discovering command-and-control communication or data exfiltration, but it is not the right source for local file creation events.
- ✗
DeviceRegistryEvents
Why it's wrong here
DeviceRegistryEvents is not the right table because it records changes to registry keys and values, such as registry value modifications and data written to the Windows Registry. Although malware may create registry persistence entries that reference a file path, the table does not log the file creation itself, and the path is only present if the malware writes it as part of its persistence mechanism. The investigation requires locating the file, not the registry modification, so this table is insufficient.
Go deeper
Related to this question
Learn chapter
Data Loss Prevention Policies
Key term
Malware
Malware is any software intentionally designed to cause damage, disrupt operations, steal data, or gain unauthorized access to computer systems.
Key term
Microsoft 365
Microsoft 365 is a subscription-based cloud service from Microsoft that combines productivity tools like Office apps with security, device management, and online storage.
About these practice questions
One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.