Courseiva

MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR

A security analyst wants to create a custom detection rule that triggers when a user receives a phishing email that bypassed Exchange Online Protection, and then clicks a link that leads to a known malicious domain. Which two advanced hunting tables should the analyst combine to detect this chain of events?

⚠ Common exam trap

The trap is that candidates may think DeviceNetworkEvents can replace EmailEvents, but network logs alone cannot prove the click originated from an email. The detection must include EmailEvents to capture the phishing email receipt, which is the initial event in the chain.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

EmailEvents and UrlClickEvents

Combining EmailEvents (which captures email delivery) with UrlClickEvents (which records user clicks on URLs in emails) allows the analyst to identify the specific chain: a user received a phishing email and then clicked a link. This pair directly links the email receipt to the user's click action. Option D is incorrect because while UrlClickEvents and DeviceNetworkEvents can correlate a click to a network connection, they do not include the email receipt event (EmailEvents), which is essential to detect the full chain described: receiving a phishing email and then clicking a link. Without EmailEvents, there is no evidence that the click originated from an email.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    EmailEvents and DeviceNetworkEvents

    Why it's wrong here

    DeviceNetworkEvents records endpoint network connections, not the URL clicks generated inside an email client, so the click-to-malicious-domain link cannot be joined. It tempts because combining email delivery data with endpoint telemetry is the usual pattern for detecting post-delivery compromise activity.

  • ✓

    EmailEvents and UrlClickEvents

    Why this is correct

    EmailEvents captures delivery-level data, including whether Exchange Online Protection allowed the message through, while UrlClickEvents records Safe Links click telemetry against the URL and its verdict. Joining them on NetworkMessageId correlates the bypassed phishing email with the subsequent malicious-domain click, satisfying the required two-stage detection chain.

  • ✗

    EmailEvents and IdentityLogonEvents

    Why it's wrong here

    IdentityLogonEvents captures authentication activity against Microsoft Entra ID, not outbound web requests to a malicious domain, so the click cannot be correlated. It tempts because pairing email events with identity telemetry is standard when hunting for credential phishing and subsequent sign-in anomalies.

  • ✗

    UrlClickEvents and DeviceNetworkEvents

    Why it's wrong here

    Incorrect. Although UrlClickEvents and DeviceNetworkEvents can link a click to subsequent network activity, they lack the email receipt information (EmailEvents). The scenario requires detection starting from the phishing email delivery, which is missing in this pair.

Go deeper

Related to this question

About these practice questions

This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.