MS-102 DeviceNetworkEvents Practice Question
A security analyst is creating a custom detection rule in Microsoft 365 Defender Advanced Hunting. The rule should trigger when a device makes an outbound connection to a known malicious IP address, and within 10 minutes, a process with suspicious command-line arguments is started on the same device. Which two Advanced Hunting tables must be joined using a KQL query to create this detection?
⚠ Common exam trap
Candidates might think that file events or other tables are also required, but the scenario specifically pairs network events with process events on the same device within a time window. Joining DeviceProcessEvents with DeviceFileEvents would be irrelevant.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DeviceNetworkEvents and DeviceProcessEvents.
The detection rule correlates an outbound network connection to a known malicious IP with a subsequent process creation on the same device within 10 minutes. This requires joining DeviceNetworkEvents (for network connections) with DeviceProcessEvents (for process creation and command-line arguments). DeviceFileEvents is not needed because the rule does not involve file events. Therefore, only Option A provides the necessary tables.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
DeviceNetworkEvents and DeviceProcessEvents.
Why this is correct
DeviceNetworkEvents supplies outbound connection records, including RemoteIP, while DeviceProcessEvents captures process starts with ProcessCommandLine. Joining both on DeviceId and aligning timestamps within the 10-minute window satisfies the correlation requirement, since no single table holds network and process-creation data together.
- ✗
DeviceEvents and DeviceLogonEvents.
Why it's wrong here
DeviceLogonEvents records authentication activity, not process creation or network connections, so joining it cannot correlate an outbound connection with a subsequent process start. DeviceNetworkEvents and DeviceProcessEvents are the tables that supply those two event types for the ten-minute window.
- ✗
DeviceProcessEvents and DeviceFileEvents.
Why it's wrong here
DeviceProcessEvents supplies the suspicious command-line start, but DeviceFileEvents records file creation, modification and deletion — not outbound network connections. It is tempting because both are device-level tables commonly joined for file-to-process correlation, such as tracing which process dropped a payload. This scenario instead requires DeviceNetworkEvents for the malicious IP connection.
- ✗
DeviceNetworkEvents and DeviceRegistryEvents.
Why it's wrong here
DeviceRegistryEvents records registry key and value modifications, which never represent an outbound connection or a process command line. It is the correct table for detecting persistence via registry run keys, not for correlating network traffic with process starts.
Go deeper
Related to this question
Learn chapter
Microsoft 365 Security Posture Improvement
Key term
Microsoft 365
Microsoft 365 is a subscription-based cloud service from Microsoft that combines productivity tools like Office apps with security, device management, and online storage.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.