Courseiva

MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR

Your organization uses Microsoft Defender for Endpoint and Microsoft Defender for Identity. A user reports that their account was used to send a large volume of email messages to internal recipients, which appears to be a potential account compromise. You need to determine if the account is compromised and if any lateral movement occurred. Which data sources should you analyze in Microsoft Defender XDR?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

IdentityLogonEvents, EmailEvents, and DeviceProcessEvents

IdentityLogonEvents (from Microsoft Defender for Identity) provide logon activities, EmailEvents (from Microsoft Defender for Office 365) show email sending patterns, and DeviceProcessEvents (from Microsoft Defender for Endpoint) reveal process creations that may indicate lateral movement (e.g., PsExec, WMI). Together, these three data sources allow correlation of identity, email, and device events to confirm a compromise and detect lateral movement. Option A is incorrect because EmailEvents and EmailAttachmentInfo cover only email context, lacking identity and lateral movement data. Option B is incorrect because DeviceNetworkEvents and DeviceProcessEvents lack identity and email context. Option C is incorrect because DeviceEvents and DeviceNetworkEvents also miss identity and email context.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    EmailEvents and EmailAttachmentInfo

    Why it's wrong here

    These tables exclusively capture email traffic, such as delivery, send actions, and attachment metadata, but they contain zero identity authentication data and no endpoint process execution telemetry. Without IdentityLogonEvents, there is no way to see whether a user's account was signed in from a suspicious location, and without DeviceProcessEvents, lateral movement executed via commands or scripts on a device would remain invisible. Thus, these tables alone cannot confirm a compromised account or trace the attack beyond the mailbox.

  • ✗

    DeviceNetworkEvents and DeviceProcessEvents

    Why it's wrong here

    This combination supplies only device-specific telemetry: network connections and process executions on endpoints, which can indicate lateral movement from a device, but it has no identity sign-in logs and no email records. Without IdentityLogonEvents, you cannot attribute the observed network connections or processes to a specific compromised user account, and without EmailEvents, you have no evidence of the original email vector that initiated the compromise. Therefore, this pair fails to connect the account-level compromise with the email evidence.

  • ✗

    DeviceEvents and DeviceNetworkEvents

    Why it's wrong here

    This pair provides general security event and network-level data, such as antivirus detections and outbound connections, but it omits both identity authentication events and email-specific activity. DeviceEvents is a broad catch-all table without the structured process-creation detail needed to identify lateral movement, while DeviceNetworkEvents alone lacks user context, making it impossible to associate the reported email with any sign-in or compromised identity. As a result, an analyst cannot validate whether a specific account was compromised or trace actions taken under that identity.

  • ✓

    IdentityLogonEvents, EmailEvents, and DeviceProcessEvents

    Why this is correct

    Together, these tables provide a complete attack chain: IdentityLogonEvents records sign-in and logon attempts, revealing suspicious authentication patterns tied to a specific account; EmailEvents tracks email send/receive activity, enabling correlation of a phishing email or malicious attachment; and DeviceProcessEvents logs process creation, which exposes lateral movement when a compromised account launches a remote service, script, or executable. Joining these tables on user SID and device ID lets an investigator reconstruct the timeline from email receipt to identity compromise to endpoint execution.

Go deeper

Related to this question

About these practice questions

This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.