nerdexam
Microsoft

SC-200 · Question #293

You have a Microsoft 365 subscription that uses Microsoft Defender XDR. You are investigating an attacker that is known to use the Microsoft Graph API as an attack vector. The attacker performs the…

The correct answer is D. Tactic1, Tactic2, and Tactic3. All listed tactics (Tactic1, Tactic2, and Tactic3) that involve using the Microsoft Graph API as an attack vector can be analyzed using the MicrosoftGraphActivityLogs table in Microsoft Defender XDR.

Submitted by sofia.br· Apr 18, 2026

Question

You have a Microsoft 365 subscription that uses Microsoft Defender XDR. You are investigating an attacker that is known to use the Microsoft Graph API as an attack vector. The attacker performs the tactics shown the following table. You need to search for malicious activities in your organization. Which tactics can you analyze by using the MicrosoftGraphActivityLogs table?

Exhibit

SC-200 question #293 exhibit

Options

  • ATactic2 only
  • BTactic1 and Tactic2 only
  • CTactic2 and Tactic3 only
  • DTactic1, Tactic2, and Tactic3

How the community answered

(56 responses)
  • A
    7% (4)
  • B
    4% (2)
  • C
    13% (7)
  • D
    77% (43)

Why each option

All listed tactics (Tactic1, Tactic2, and Tactic3) that involve using the Microsoft Graph API as an attack vector can be analyzed using the MicrosoftGraphActivityLogs table in Microsoft Defender XDR.

ATactic2 only

This is incorrect because the `MicrosoftGraphActivityLogs` table can track more activities than just Tactic2, providing comprehensive visibility into Graph API operations.

BTactic1 and Tactic2 only

This is incorrect because the `MicrosoftGraphActivityLogs` table can track more activities than just Tactic1 and Tactic2, offering a broader scope of analysis.

CTactic2 and Tactic3 only

This is incorrect because the `MicrosoftGraphActivityLogs` table can track more activities than just Tactic2 and Tactic3, ensuring full coverage of Graph API-related attacks.

DTactic1, Tactic2, and Tactic3Correct

The `MicrosoftGraphActivityLogs` table in Microsoft Defender XDR provides detailed information about activities performed via the Microsoft Graph API, enabling the detection and analysis of various attack tactics that leverage this API, covering all types of malicious activities specified. This table specifically logs all operations made to the Microsoft Graph API, allowing for comprehensive investigation into any attacker actions taken through this interface.

Concept tested: Microsoft Defender XDR hunting table for Microsoft Graph API activities

Source: https://learn.microsoft.com/en-us/microsoft-365/security/defender/advanced-hunting-microsoftgraphactivitylogs-table

Community Discussion

No community discussion yet for this question.

Full SC-200 Practice