Courseiva

MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR

Your organization uses Microsoft Defender for Identity. You receive an alert about a potential DCSync attack. What should you do to investigate this alert in Microsoft Defender XDR?

⚠ Common exam trap

Many exam-takers confuse the different Advanced Hunting tables: they assume DCSync is an LDAP query (Option B) or a directory object change (Option A), when in fact it is a replication protocol event logged in IdentityLogonEvents.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Run a KQL query in Advanced Hunting against IdentityLogonEvents to identify suspicious replication attempts.

DCSync attacks are performed by requesting domain replication via the MS-DRSR protocol, which generates specific directory replication events. In Microsoft Defender XDR, these replication attempts are logged in the IdentityLogonEvents table when an account authenticates to a domain controller for replication purposes. Running a KQL query against this table allows you to identify the source account, target domain controller, and the specific replication activity that triggered the alert.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Review the IdentityDirectoryEvents table for replication-related events.

    Why it's wrong here

    IdentityDirectoryEvents logs directory object changes, such as attribute modifications or group membership updates, not authentication or replication access patterns. A DCSync-style replication attempt does not modify directory objects directly; it performs DRSUAPI calls, so querying this table would miss the actual replication events and only show post-hoc changes if any were made. Therefore, this table is not the correct source for identifying suspicious replication attempts.

  • ✗

    Use IdentityQueryEvents to find LDAP queries related to replication.

    Why it's wrong here

    IdentityQueryEvents captures LDAP queries sent to Active Directory, which can sometimes precede a replication attempt. However, the actual replication operation uses DRSUAPI over the Directory Replication Service Remote Protocol, not LDAP, and is recorded as a logon event, not a query event. Thus, querying IdentityQueryEvents would only reveal enumeration or reconnaissance, not the replication attempt itself, making it an insufficient and incorrect choice.

  • ✗

    Check the IdentityAlertEvents table to see if the alert has additional context.

    Why it's wrong here

    IdentityAlertEvents contains high-level security alerts generated by Defender for Identity, such as a suspected DCSync attack, but it does not provide the raw logon-level data needed to investigate or identify the specific replication attempt. Alerts are triggered based on detections, whereas you need to look at the underlying security events to confirm and analyze the attack behavior. Therefore, checking this table only gives you alert metadata, not the granular evidence required for investigation.

  • ✓

    Run a KQL query in Advanced Hunting against IdentityLogonEvents to identify suspicious replication attempts.

    Why this is correct

    IdentityLogonEvents is the correct table because it records authentication and logon events, including those that occur when an account attempts to replicate domain data via DRSUAPI. During a DCSync attack, the attacker's replication request appears as a logon event with specific attributes, such as a particular logon type or the use of replication privileges. Running a KQL query against IdentityLogonEvents allows you to filter for these suspicious patterns, such as account names, source IPs, and timing, making it the proper source for identifying replication attempts in Advanced Hunting.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

Go deeper

Related to this question

About these practice questions

One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.