MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
Your organization uses Microsoft Defender for Endpoint and Microsoft Defender for Identity. A user reports that their account was used to send a large volume of email messages to internal recipients, which appears to be a potential account compromise. You need to determine if the account is compromised and if any lateral movement occurred. Which data sources should you analyze in Microsoft Defender XDR?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
IdentityLogonEvents, EmailEvents, and DeviceProcessEvents
IdentityLogonEvents (from Microsoft Defender for Identity) provide logon activities, EmailEvents (from Microsoft Defender for Office 365) show email sending patterns, and DeviceProcessEvents (from Microsoft Defender for Endpoint) reveal process creations that may indicate lateral movement (e.g., PsExec, WMI). Together, these three data sources allow correlation of identity, email, and device events to confirm a compromise and detect lateral movement. Option A is incorrect because EmailEvents and EmailAttachmentInfo cover only email context, lacking identity and lateral movement data. Option B is incorrect because DeviceNetworkEvents and DeviceProcessEvents lack identity and email context. Option C is incorrect because DeviceEvents and DeviceNetworkEvents also miss identity and email context.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
EmailEvents and EmailAttachmentInfo
Why it's wrong here
These tables exclusively capture email traffic, such as delivery, send actions, and attachment metadata, but they contain zero identity authentication data and no endpoint process execution telemetry. Without IdentityLogonEvents, there is no way to see whether a user's account was signed in from a suspicious location, and without DeviceProcessEvents, lateral movement executed via commands or scripts on a device would remain invisible. Thus, these tables alone cannot confirm a compromised account or trace the attack beyond the mailbox.
- ✗
DeviceNetworkEvents and DeviceProcessEvents
Why it's wrong here
This combination supplies only device-specific telemetry: network connections and process executions on endpoints, which can indicate lateral movement from a device, but it has no identity sign-in logs and no email records. Without IdentityLogonEvents, you cannot attribute the observed network connections or processes to a specific compromised user account, and without EmailEvents, you have no evidence of the original email vector that initiated the compromise. Therefore, this pair fails to connect the account-level compromise with the email evidence.
- ✗
DeviceEvents and DeviceNetworkEvents
Why it's wrong here
This pair provides general security event and network-level data, such as antivirus detections and outbound connections, but it omits both identity authentication events and email-specific activity. DeviceEvents is a broad catch-all table without the structured process-creation detail needed to identify lateral movement, while DeviceNetworkEvents alone lacks user context, making it impossible to associate the reported email with any sign-in or compromised identity. As a result, an analyst cannot validate whether a specific account was compromised or trace actions taken under that identity.
- ✓
IdentityLogonEvents, EmailEvents, and DeviceProcessEvents
Why this is correct
Together, these tables provide a complete attack chain: IdentityLogonEvents records sign-in and logon attempts, revealing suspicious authentication patterns tied to a specific account; EmailEvents tracks email send/receive activity, enabling correlation of a phishing email or malicious attachment; and DeviceProcessEvents logs process creation, which exposes lateral movement when a compromised account launches a remote service, script, or executable. Joining these tables on user SID and device ID lets an investigator reconstruct the timeline from email receipt to identity compromise to endpoint execution.
Go deeper
Related to this question
Learn chapter
Email Quarantine and Submission Management
Key term
XDR
XDR, or Extended Detection and Response, is a unified security platform that collects and correlates data across multiple security layers—endpoints, networks, servers, cloud workloads, and email—to improve threat detection and enable faster response.
Key term
Defender for Office 365
Microsoft Defender for Office 365 is a cloud-based email security service that protects organizations against advanced threats like phishing, malware, and business email compromise by scanning emails, attachments, and links in real time.
About these practice questions
This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.