MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
You are investigating a phishing campaign targeting your organization. In Microsoft Defender XDR, you run a KQL query in Advanced Hunting to find all email messages that contain a specific phishing URL. Which table should you query?
⚠ Common exam trap
Watch out — candidates often confuse UrlClickEvents (which tracks user interaction after delivery) with EmailUrlInfo (which captures URL presence in the email itself), leading them to choose the wrong table for identifying messages containing a URL.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
EmailUrlInfo
The EmailUrlInfo table in Advanced Hunting stores URL information extracted from email messages, including the specific URLs found in the body or attachments. To find all email messages containing a specific phishing URL, you must query this table because it directly maps URLs to their associated email identifiers (e.g., NetworkMessageId).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
EmailUrlInfo
Why this is correct
In Advanced hunting, EmailUrlInfo is the table that stores URL entities extracted from email messages, with each record tied to a specific email via NetworkMessageId. When investigating a phishing campaign, you use this table to search for messages containing a malicious URL or to pivot from a known email to all its embedded links. It also includes the URL's disposition (e.g., Phish) from Microsoft's threat reputation systems, making it the correct source for email-level URL information.
- ✗
EmailAttachmentInfo
Why it's wrong here
EmailAttachmentInfo is the Advanced hunting table for file metadata attached to messages, such as filename, SHA-256, and file threat verdict. It does not expose URLs in the message body, which are stored separately in EmailUrlInfo. Even if the phishing payload is an HTML attachment with an embedded link, EmailAttachmentInfo only tells you about the attachment file itself, not the URL content inside that file. Therefore it cannot directly answer which phishing URLs were sent in the emails.
- ✗
UrlClickEvents
Why it's wrong here
UrlClickEvents logs user clicks on URLs in email messages, including the URL, the user who clicked, and the Safe Links verdict at the time of the click. This table is only populated when a recipient actively clicks a link that is processed by Safe Links; an unclicked malicious URL in a phishing email will not appear. For the investigation described, you need URL presence in the message, not click behavior, so UrlClickEvents would miss the campaign emails sitting unopened in inboxes.
- ✗
EmailEvents
Why it's wrong here
EmailEvents provides email-flow and delivery metadata, such as senders, recipients, delivery actions, and MessageIDs, but its columns do not include the individual URLs found in the message body. It is useful for correlating which mailboxes received a phishing email after EmailUrlInfo identifies a malicious link, but by itself it cannot show the URL indicators. Since the question targets URL information from the email itself, EmailEvents is too high-level and lacks the URL-specific details needed.
Go deeper
Related to this question
Learn chapter
Defender for Endpoint Deployment via Intune
Key term
XDR
XDR, or Extended Detection and Response, is a unified security platform that collects and correlates data across multiple security layers—endpoints, networks, servers, cloud workloads, and email—to improve threat detection and enable faster response.
Key term
Microsoft Defender XDR
Microsoft Defender XDR is a unified security platform that automatically correlates alerts from across an organization's endpoints, email, identities, and cloud apps to stop complex attacks.
About these practice questions
Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.