MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
A security analyst wants to create a custom detection rule in Microsoft Defender XDR that triggers when a user receives a phishing email and clicks a link to a known malicious domain. Which advanced hunting table should the analyst query to track the clicked URL?
⚠ Common exam trap
Candidates often confuse EmailUrlInfo (which stores URL metadata and supports click tracking) with EmailEvents (which only contains email flow data), leading them to incorrectly select EmailEvents as the primary table for URL click analysis.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
EmailUrlInfo
The EmailUrlInfo table in Advanced Hunting for Microsoft Defender XDR contains records of URLs that were present in emails, including the URL domain and whether the link was clicked. By joining EmailEvents with EmailUrlInfo on the NetworkMessageId, the analyst can identify when a user clicked a URL that leads to a known malicious domain, making it the correct table for tracking clicked URLs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
EmailEvents
Why it's wrong here
Provides the delivery envelope and message-level metadata, such as sender/recipient, subject, and delivery status. It does not contain the actual URL string or any click/verdict data for links within the email body. So while it's necessary for context (e.g., who received the email), it alone cannot be the source for a URL click detection rule.
- ✓
EmailUrlInfo
Why this is correct
This table is the authoritative source in the email schema for URL information, including the original URL, domain, and the disposition (e.g., clicked, not clicked) associated with links in emails. It's directly structured for link-level analysis and is the correct starting point when building a custom detection for clicked URLs. You can join it with EmailEvents on NetworkMessageId to correlate click events with the email's delivery and recipient.
- ✗
EmailAttachmentInfo
Why it's wrong here
This table is designed for attachment-centric hunting, exposing fields like SHA256, filename, and file size, not the links embedded in the email body. Therefore, even if an attachment is benign, a malicious URL could go undetected. It cannot answer "did the user click the link?" because it never records click activity on URLs.
- ✗
DeviceEvents
Why it's wrong here
Even though user clicks happen on an endpoint (browser), DeviceEvents records process creations, registry modifications, and network connections at the OS level. It does not contain the email's original URL or the email-specific context like NetworkMessageId. Browsers might have network events, but they are not filtered to email URLs and lack the email/URL association that EmailUrlInfo provides.
Go deeper
Related to this question
Learn chapter
Defender for Endpoint Deployment via Intune
Key term
Microsoft Defender XDR
Microsoft Defender XDR is a unified security platform that automatically correlates alerts from across an organization's endpoints, email, identities, and cloud apps to stop complex attacks.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.