MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
A security analyst wants to create a custom detection rule that triggers when a user receives a phishing email that bypassed Exchange Online Protection, and then clicks a link that leads to a known malicious domain. Which two advanced hunting tables should the analyst combine to detect this chain of events?
⚠ Common exam trap
The trap is that candidates may think DeviceNetworkEvents can replace EmailEvents, but network logs alone cannot prove the click originated from an email. The detection must include EmailEvents to capture the phishing email receipt, which is the initial event in the chain.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
EmailEvents and UrlClickEvents
Combining EmailEvents (which captures email delivery) with UrlClickEvents (which records user clicks on URLs in emails) allows the analyst to identify the specific chain: a user received a phishing email and then clicked a link. This pair directly links the email receipt to the user's click action. Option D is incorrect because while UrlClickEvents and DeviceNetworkEvents can correlate a click to a network connection, they do not include the email receipt event (EmailEvents), which is essential to detect the full chain described: receiving a phishing email and then clicking a link. Without EmailEvents, there is no evidence that the click originated from an email.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
EmailEvents and DeviceNetworkEvents
Why it's wrong here
DeviceNetworkEvents records endpoint network connections, not the URL clicks generated inside an email client, so the click-to-malicious-domain link cannot be joined. It tempts because combining email delivery data with endpoint telemetry is the usual pattern for detecting post-delivery compromise activity.
- ✓
EmailEvents and UrlClickEvents
Why this is correct
EmailEvents captures delivery-level data, including whether Exchange Online Protection allowed the message through, while UrlClickEvents records Safe Links click telemetry against the URL and its verdict. Joining them on NetworkMessageId correlates the bypassed phishing email with the subsequent malicious-domain click, satisfying the required two-stage detection chain.
- ✗
EmailEvents and IdentityLogonEvents
Why it's wrong here
IdentityLogonEvents captures authentication activity against Microsoft Entra ID, not outbound web requests to a malicious domain, so the click cannot be correlated. It tempts because pairing email events with identity telemetry is standard when hunting for credential phishing and subsequent sign-in anomalies.
- ✗
UrlClickEvents and DeviceNetworkEvents
Why it's wrong here
Incorrect. Although UrlClickEvents and DeviceNetworkEvents can link a click to subsequent network activity, they lack the email receipt information (EmailEvents). The scenario requires detection starting from the phishing email delivery, which is missing in this pair.
Go deeper
Related to this question
Learn chapter
Exchange Journaling and Mail Export
Key term
Exchange Online
Exchange Online is Microsoft's cloud-based email, calendar, and contact hosting service that is part of the Microsoft 365 suite, allowing organizations to manage corporate messaging without maintaining their own mail servers.
Key term
Phishing
Phishing is a type of cyber attack where criminals impersonate legitimate organizations or individuals to trick victims into revealing sensitive information such as passwords, credit card numbers, or personal data.
About these practice questions
This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.