SC-200 · Question #293
You have a Microsoft 365 subscription that uses Microsoft Defender XDR. You are investigating an attacker that is known to use the Microsoft Graph API as an attack vector. The attacker performs the…
The correct answer is D. Tactic1, Tactic2, and Tactic3. All listed tactics (Tactic1, Tactic2, and Tactic3) that involve using the Microsoft Graph API as an attack vector can be analyzed using the MicrosoftGraphActivityLogs table in Microsoft Defender XDR.
Question
You have a Microsoft 365 subscription that uses Microsoft Defender XDR. You are investigating an attacker that is known to use the Microsoft Graph API as an attack vector. The attacker performs the tactics shown the following table. You need to search for malicious activities in your organization. Which tactics can you analyze by using the MicrosoftGraphActivityLogs table?
Exhibit
Options
- ATactic2 only
- BTactic1 and Tactic2 only
- CTactic2 and Tactic3 only
- DTactic1, Tactic2, and Tactic3
How the community answered
(56 responses)- A7% (4)
- B4% (2)
- C13% (7)
- D77% (43)
Why each option
All listed tactics (Tactic1, Tactic2, and Tactic3) that involve using the Microsoft Graph API as an attack vector can be analyzed using the MicrosoftGraphActivityLogs table in Microsoft Defender XDR.
This is incorrect because the `MicrosoftGraphActivityLogs` table can track more activities than just Tactic2, providing comprehensive visibility into Graph API operations.
This is incorrect because the `MicrosoftGraphActivityLogs` table can track more activities than just Tactic1 and Tactic2, offering a broader scope of analysis.
This is incorrect because the `MicrosoftGraphActivityLogs` table can track more activities than just Tactic2 and Tactic3, ensuring full coverage of Graph API-related attacks.
The `MicrosoftGraphActivityLogs` table in Microsoft Defender XDR provides detailed information about activities performed via the Microsoft Graph API, enabling the detection and analysis of various attack tactics that leverage this API, covering all types of malicious activities specified. This table specifically logs all operations made to the Microsoft Graph API, allowing for comprehensive investigation into any attacker actions taken through this interface.
Concept tested: Microsoft Defender XDR hunting table for Microsoft Graph API activities
Source: https://learn.microsoft.com/en-us/microsoft-365/security/defender/advanced-hunting-microsoftgraphactivitylogs-table
Community Discussion
No community discussion yet for this question.
