Courseiva

MS-102 DeviceNetworkEvents Practice Question

A security analyst is creating a custom detection rule in Microsoft 365 Defender Advanced Hunting. The rule should trigger when a device makes an outbound connection to a known malicious IP address, and within 10 minutes, a process with suspicious command-line arguments is started on the same device. Which two Advanced Hunting tables must be joined using a KQL query to create this detection?

⚠ Common exam trap

Candidates might think that file events or other tables are also required, but the scenario specifically pairs network events with process events on the same device within a time window. Joining DeviceProcessEvents with DeviceFileEvents would be irrelevant.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

DeviceNetworkEvents and DeviceProcessEvents.

The detection rule correlates an outbound network connection to a known malicious IP with a subsequent process creation on the same device within 10 minutes. This requires joining DeviceNetworkEvents (for network connections) with DeviceProcessEvents (for process creation and command-line arguments). DeviceFileEvents is not needed because the rule does not involve file events. Therefore, only Option A provides the necessary tables.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    DeviceNetworkEvents and DeviceProcessEvents.

    Why this is correct

    DeviceNetworkEvents supplies outbound connection records, including RemoteIP, while DeviceProcessEvents captures process starts with ProcessCommandLine. Joining both on DeviceId and aligning timestamps within the 10-minute window satisfies the correlation requirement, since no single table holds network and process-creation data together.

  • ✗

    DeviceEvents and DeviceLogonEvents.

    Why it's wrong here

    DeviceLogonEvents records authentication activity, not process creation or network connections, so joining it cannot correlate an outbound connection with a subsequent process start. DeviceNetworkEvents and DeviceProcessEvents are the tables that supply those two event types for the ten-minute window.

  • ✗

    DeviceProcessEvents and DeviceFileEvents.

    Why it's wrong here

    DeviceProcessEvents supplies the suspicious command-line start, but DeviceFileEvents records file creation, modification and deletion — not outbound network connections. It is tempting because both are device-level tables commonly joined for file-to-process correlation, such as tracing which process dropped a payload. This scenario instead requires DeviceNetworkEvents for the malicious IP connection.

  • ✗

    DeviceNetworkEvents and DeviceRegistryEvents.

    Why it's wrong here

    DeviceRegistryEvents records registry key and value modifications, which never represent an outbound connection or a process command line. It is the correct table for detecting persistence via registry run keys, not for correlating network traffic with process starts.

About these practice questions

This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.