Analyzing Microsoft Graph API attack tactics through the MicrosoftGraphActivityLogs advanced-hunting table

Investigate Microsoft 365 activities to identify threats
Answer Correct answer: D — The MicrosoftGraphActivityLogs table records all Microsoft Graph API activity, so all listed tactics are analyzable there.

You have a Microsoft 365 subscription that uses Microsoft Defender XDR. You are investigating an attacker that is known to use the Microsoft Graph API as an attack vector. The attacker performs the tactics shown the following table. You need to search for malicious activities in your organization. Which tactics can you analyze by using the MicrosoftGraphActivityLogs table? - image

  1. Tactic2 only
  2. Tactic1 and Tactic2 only
  3. Tactic2 and Tactic3 only
  4. Tactic1, Tactic2, and Tactic3 Correct Answer

Community Votes

D
100%

100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The MicrosoftGraphActivityLogs table in advanced hunting captures Microsoft Graph API activity across the tenant, making it the single source to investigate any tactic expressed through Graph API calls.

When an attacker uses the Microsoft Graph API as a vector, all Graph API call activity is recorded in the MicrosoftGraphActivityLogs table, so every tactic that manifests as Graph calls can be analyzed there.

Assuming only one tactic is visible — because the table logs all Graph API activity, any tactic carried out via Graph calls (not just one) is analyzable there.

Community Discussion (4 comments)

Avaris 👍 5 Selected: D
all 3 can be used checked it with copilot
smanzana 👍 1
C is correct
Vokuhila 👍 4 Selected: D
all 3 can be used
laddu001 👍 3
actic1, Tactic2, and Tactic3

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Microsoft Defender XDR advanced hunting provides the MicrosoftGraphActivityLogs table, which records Microsoft Graph API activity in the tenant. Any attacker tactic executed through the Graph API is captured there, so all listed tactics that are expressed as Graph calls can be analyzed using this table.

Why the Other Options Are Wrong

Selecting only Tactic2 (A) or subsets (B, C) undercounts the coverage; the table logs all Graph API activity, so all tactics performed via Graph are analyzable, not just one or two.

Community Comment Notes

The community favors D (all three, 100 votes). Avaris and Vokuhila note all three can be analyzed via the table, confirming the comprehensive coverage of MicrosoftGraphActivityLogs.

Official Reference

Related Analysis

Practice All SC-200 Questions

Access 80 questions with complete answers and detailed explanations.

View Full SC-200 Practice Test →

← Back to SC-200 Study Guide