Microsoft 365 Certified: Administrator ExpertImplement and manage Microsoft Defender XDRMedium

A Microsoft 365 administrator is investigating a series of failed login attempts against cloud applications. The administrator suspects a credential stuffing attack. To gain deeper insights into the source IPs, user agents, and success/failure rates, the administrator needs to query activity logs. Which KQL table in Microsoft Defender for Cloud Apps should the administrator query?

  1. AIdentityLogonEvents
  2. BEmailEvents
  3. CDeviceNetworkEvents
  4. DCloudAppEvents
Show answer & explanation

Correct answer: D. CloudAppEvents

The `CloudAppEvents` table in Microsoft Defender for Cloud Apps contains information about activities performed in connected cloud applications. This includes login attempts (both successful and failed), user agents, source IP addresses, and other relevant details critical for investigating attacks like credential stuffing against cloud services. `IdentityLogonEvents` is for Defender for Identity, `EmailEvents` for Defender for Office 365, and `DeviceNetworkEvents` for Defender for Endpoint.

Why the other options are wrong

  • A. This table is part of Defender for Identity and focuses on logon events detected by its sensors, primarily relevant for on-premises Active Directory or hybrid identity scenarios analyzed by DfI.
  • B. This table is used by Defender for Office 365 for email-related events, not cloud application login attempts.
  • C. This table is part of Defender for Endpoint and records network connections made by devices, not cloud application login attempts.

CloudAppEvents KQL Table

The `CloudAppEvents` KQL table in Microsoft Defender for Cloud Apps contains records of activities performed by users and applications within connected cloud services.

  • Includes login attempts (success/failure).
  • Records user agents, IP addresses, activity types.
  • Crucial for investigating cloud app security incidents.
  • Used in Advanced Hunting queries.

Memory trick: Remember, 'Cloud App' 'Events' are found in the 'CloudAppEvents' table for 'Cloud' 'Login' 'Investigations'.

More Implement and manage Microsoft Defender XDR questions