Courseiva

MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR

You are a security analyst. You need to investigate a potential malware outbreak on a device using Microsoft Defender XDR. Which three data sources can you include in an advanced hunting query to gather relevant information? (Choose three.)

⚠ Common exam trap

MS-102 often tests the distinction between device-centric and cloud/email-centric data sources — candidates may incorrectly include CloudAppEvents or EmailAttachmentInfo, which are not device-focused, when asked about malware on a device.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

DeviceFileEvents

DeviceFileEvents (B) is correct because it records file creation, modification, and other file-system activity on the endpoint, which is essential for tracing malware dropped or modified files during an outbreak. DeviceNetworkEvents (D) is correct because it captures network connections and related telemetry, allowing you to identify command-and-control traffic, lateral movement, or data exfiltration tied to the malware. DeviceProcessEvents (E) is correct because it logs process creation and execution details, letting you trace malicious process trees, parent-child relationships, and command lines used by the malware. CloudAppEvents (A) is not among the marked answers because it covers cloud app and SaaS activity rather than endpoint malware artifacts, and EmailAttachmentInfo (C) is not marked because it concerns email attachment metadata, which is relevant to phishing delivery but not to the endpoint-focused advanced hunting sources selected here.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    CloudAppEvents

    Why it's wrong here

    CloudAppEvents records activity from cloud applications and services, not endpoint process, file, or registry events generated during a malware outbreak on a device. It is the correct table when investigating suspicious SaaS activity, such as anomalous file sharing or sign-ins.

  • ✓

    DeviceFileEvents

    Why this is correct

    DeviceFileEvents records file creation, modification and deletion activity on endpoints, so it surfaces the file writes and drops that malware typically performs. Including it in the advanced hunting query satisfies the requirement to gather device-level file telemetry alongside the other chosen sources.

  • ✗

    EmailAttachmentInfo

    Why it's wrong here

    EmailAttachmentInfo covers attachment metadata for email messages, so it returns no device process, file, or network telemetry needed to trace malware execution on an endpoint. It is the correct table when hunting email-borne threats such as malicious attachments, not device-level malware outbreaks.

  • ✓

    DeviceNetworkEvents

    Why this is correct

    DeviceNetworkEvents holds network connection telemetry from Defender for Endpoint, including remote IPs, ports and initiating processes. Malware command-and-control or exfiltration traffic appears here, making it a relevant source for tracing outbreak activity on the device.

  • ✓

    DeviceProcessEvents

    Why this is correct

    DeviceProcessEvents records process creation and related telemetry from Defender for Endpoint, letting you trace malicious executions, parent-child process chains and command-line arguments during the outbreak. It satisfies the requirement to include endpoint process telemetry in the advanced hunting query, exposing the malware's execution activity across affected devices.

Go deeper

Related to this question

About these practice questions

One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.