MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
You are a security analyst. You need to investigate a potential malware outbreak on a device using Microsoft Defender XDR. Which three data sources can you include in an advanced hunting query to gather relevant information? (Choose three.)
⚠ Common exam trap
MS-102 often tests the distinction between device-centric and cloud/email-centric data sources — candidates may incorrectly include CloudAppEvents or EmailAttachmentInfo, which are not device-focused, when asked about malware on a device.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DeviceFileEvents
DeviceFileEvents (B) is correct because it records file creation, modification, and other file-system activity on the endpoint, which is essential for tracing malware dropped or modified files during an outbreak. DeviceNetworkEvents (D) is correct because it captures network connections and related telemetry, allowing you to identify command-and-control traffic, lateral movement, or data exfiltration tied to the malware. DeviceProcessEvents (E) is correct because it logs process creation and execution details, letting you trace malicious process trees, parent-child relationships, and command lines used by the malware. CloudAppEvents (A) is not among the marked answers because it covers cloud app and SaaS activity rather than endpoint malware artifacts, and EmailAttachmentInfo (C) is not marked because it concerns email attachment metadata, which is relevant to phishing delivery but not to the endpoint-focused advanced hunting sources selected here.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
CloudAppEvents
Why it's wrong here
CloudAppEvents records activity from cloud applications and services, not endpoint process, file, or registry events generated during a malware outbreak on a device. It is the correct table when investigating suspicious SaaS activity, such as anomalous file sharing or sign-ins.
- ✓
DeviceFileEvents
Why this is correct
DeviceFileEvents records file creation, modification and deletion activity on endpoints, so it surfaces the file writes and drops that malware typically performs. Including it in the advanced hunting query satisfies the requirement to gather device-level file telemetry alongside the other chosen sources.
- ✗
EmailAttachmentInfo
Why it's wrong here
EmailAttachmentInfo covers attachment metadata for email messages, so it returns no device process, file, or network telemetry needed to trace malware execution on an endpoint. It is the correct table when hunting email-borne threats such as malicious attachments, not device-level malware outbreaks.
- ✓
DeviceNetworkEvents
Why this is correct
DeviceNetworkEvents holds network connection telemetry from Defender for Endpoint, including remote IPs, ports and initiating processes. Malware command-and-control or exfiltration traffic appears here, making it a relevant source for tracing outbreak activity on the device.
- ✓
DeviceProcessEvents
Why this is correct
DeviceProcessEvents records process creation and related telemetry from Defender for Endpoint, letting you trace malicious executions, parent-child process chains and command-line arguments during the outbreak. It satisfies the requirement to include endpoint process telemetry in the advanced hunting query, exposing the malware's execution activity across affected devices.
Go deeper
Related to this question
Learn chapter
Attack Simulation Training in Defender
Key term
Microsoft Defender XDR
Microsoft Defender XDR is a unified security platform that automatically correlates alerts from across an organization's endpoints, email, identities, and cloud apps to stop complex attacks.
Key term
Phishing
Phishing is a type of cyber attack where criminals impersonate legitimate organizations or individuals to trick victims into revealing sensitive information such as passwords, credit card numbers, or personal data.
About these practice questions
One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.