MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
A security analyst needs to create a custom detection rule in Microsoft Defender XDR that triggers when a user's device establishes a network connection to a known malicious IP address on a port commonly used by a specific malware. The rule must also include process information such as the filename of the process that initiated the connection. Which advanced hunting table should be the primary data source for this rule?
⚠ Common exam trap
Many exam-takers confuse DeviceProcessEvents (which includes process command lines) as sufficient for network detection, overlooking that it lacks the network-specific fields (RemoteIP, RemotePort) required to match a malicious IP and port combination.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DeviceNetworkEvents
The DeviceNetworkEvents table in Microsoft Defender XDR captures network connection events, including source and destination IP addresses, ports, and the initiating process's filename and ID. This makes it the ideal primary data source for a custom detection rule that must trigger on a specific malicious IP and port combination while also providing process information.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
DeviceNetworkEvents
Why this is correct
DeviceNetworkEvents is the correct table because it records each network connection initiated or received on a device, including actionable fields such as RemoteIP, RemotePort, Protocol, LocalIP, LocalPort, and InitiatingProcessId or InitiatingProcessFileName. A custom detection rule can directly target these columns to alert on inbound or outbound traffic to suspicious IPs or ports without needing to join other tables. This is the only listed table that natively contains network-specific endpoint data suitable for detecting network-based threats.
- ✗
DeviceProcessEvents
Why it's wrong here
DeviceProcessEvents stores process creation and termination metadata—such as ProcessCommandLine, ParentProcessId, and FileName—but does not include the destination IP address, port, or protocol of any network communication. While you could join DeviceProcessEvents to DeviceNetworkEvents on ProcessId to relate a process to its connections, the process event itself is insufficient for a rule that must filter on remote network endpoints. Therefore this table alone cannot serve as the primary schema for a network-connection detection rule.
- ✗
DeviceFileEvents
Why it's wrong here
DeviceFileEvents tracks filesystem activity including file creation, modification, renaming, and deletion, with details like FolderPath, FileName, and SHA256 hash. It contains no network-specific attributes like remote IP addresses or port numbers, so it cannot identify network connections or the destination of a transfer. Although a detection rule for malware downloads might reference both file and network events, FileEvents on its own provides no endpoint network visibility.
- ✗
IdentityLogonEvents
Why it's wrong here
IdentityLogonEvents captures authentication and sign-in activity for identities—such as AccountUpn, LogonType, and TargetDeviceName—and belongs to the IdentityLogonEvents schema in Microsoft 365 Defender. It is unrelated to endpoint network connections and has no fields for remote IP, remote port, or network protocol. A custom detection that needs to flag outbound connections from a device, rather than a user logon, would be using the wrong data source.
Go deeper
Related to this question
Learn chapter
Microsoft 365 Security Posture Improvement
Key term
Malware
Malware is any software intentionally designed to cause damage, disrupt operations, steal data, or gain unauthorized access to computer systems.
Key term
XDR
XDR, or Extended Detection and Response, is a unified security platform that collects and correlates data across multiple security layers—endpoints, networks, servers, cloud workloads, and email—to improve threat detection and enable faster response.
About these practice questions
Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.