Microsoft 365 Certified: Administrator ExpertImplement and manage Microsoft Defender XDRMedium

A security operations center (SOC) team uses Microsoft Defender XDR and frequently performs advanced hunting queries to proactively search for threats. They need to create a custom detection rule that identifies any new executable files (EXE) created on critical servers from a remote share, specifically looking for files that have not been observed before within the organization. The rule should trigger an alert if such an event occurs. Which Advanced Hunting table should be the primary source for detecting new file creations on devices?

  1. ADeviceNetworkEvents
  2. BDeviceFileEvents
  3. CDeviceRegistryEvents
  4. DDeviceProcessEvents
Show answer & explanation

Correct answer: B. DeviceFileEvents

The DeviceFileEvents table records events related to file creation, modification, deletion, and access on devices. This table is the most appropriate source for detecting 'new executable files created' on servers, especially when combined with criteria to check if the file has been observed before.

Why the other options are wrong

  • A. DeviceNetworkEvents records network connections and traffic, not file system changes.
  • C. DeviceRegistryEvents monitors changes to the system registry, which is not directly related to file creation.
  • D. DeviceProcessEvents tracks process creation, termination, and modifications, not specific file creation events.

Advanced Hunting DeviceFileEvents Table

The DeviceFileEvents table in Microsoft Defender XDR Advanced Hunting contains information about file system activities on devices, including file creation, modification, deletion, and access. It is crucial for detecting suspicious file operations and identifying new or unauthorized files.

  • Records file creation, modification, deletion, and access.
  • Provides details like file name, path, hash, and action type.
  • Essential for detecting new executables or malware drops.
  • Used to track sensitive file interactions.

Memory trick: DeviceFileEvents is like the file cabinet's security log, tracking every file that comes in or out.

More Implement and manage Microsoft Defender XDR questions