Microsoft Security Operations AnalystMitigate threats using Microsoft Defender XDRMedium
A security analyst is investigating a potential insider threat where an employee is suspected of exfiltrating sensitive data. The analyst needs to review all activities performed by this specific user across various cloud applications, including file access, downloads, and logins, over the past week. Which specific data table in Advanced Hunting should the analyst query to gather this comprehensive information?
- ACloudAppEvents
- BIdentityLogonEvents
- CDeviceProcessEvents
- DEmailEvents
Show answer & explanationAnswer & explanation
Correct answer: A. CloudAppEvents
CloudAppEvents captures a wide range of activities performed by users within monitored cloud applications, including file access, downloads, and other interactions, making it the ideal table for investigating comprehensive user activity in cloud apps.
Why the other options are wrong
- B. IdentityLogonEvents tracks login activities for identities, but not the detailed in-app actions like file access and downloads within cloud applications.
- C. DeviceProcessEvents tracks processes on endpoints, not activities within cloud applications.
- D. EmailEvents tracks email-related activities, not general cloud application usage.
Advanced Hunting: CloudAppEvents
An Advanced Hunting table in Microsoft Defender XDR that contains information about activities performed in cloud applications monitored by Microsoft Defender for Cloud Apps.
- Records user activities in cloud apps.
- Includes file access, downloads, logins, uploads.
- Essential for investigating cloud-based insider threats.
Memory trick: For 'cloud app' activities like downloads, look in 'CloudAppEvents'.