MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
A security analyst needs to identify the specific process (filename) that initiated a network connection from a device to a known malicious IP address over the last 24 hours. Which advanced hunting table in Microsoft Defender XDR provides the necessary data including the initiating process filename and the remote IP address?
⚠ Common exam trap
Candidates often confuse DeviceProcessEvents (which shows process creation) with network connection data, mistakenly thinking that process events include network details, but DeviceProcessEvents lacks the RemoteIP field entirely.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DeviceNetworkEvents
DeviceNetworkEvents is the correct table because it specifically captures network connection events, including the initiating process filename (InitiatingProcessFileName) and the remote IP address (RemoteIP). This table is designed for hunting network-related activities, such as connections to known malicious IPs, within Microsoft Defender XDR's advanced hunting schema.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
DeviceNetworkEvents
Why this is correct
DeviceNetworkEvents is the Advanced Hunting table that records network connections observed on a device, with dedicated columns such as RemoteIP, RemotePort, LocalIP, LocalPort, Protocol, and the initiating process details (InitiatingProcessId, InitiatingProcessFileName). To identify the specific process that made a given network connection, an analyst can query this table and filter by the remote endpoint or timestamp, then read the initiating process information directly. This is the only table in the Advanced Hunting schema purpose-built for correlating process activity with network endpoints.
- ✗
DeviceProcessEvents
Why it's wrong here
DeviceProcessEvents contains process creation and termination events, capturing the command line, image path, parent process, and user account for each newly launched process. While this table is useful for understanding what was executed on a device, it does not include any network-specific columns such as remote IP, port, or connection state, so it cannot tell you what network connection a process made. Even if you find the process name in this table, you would have to separately join to network events to see its outbound activity.
- ✗
DeviceEvents
Why it's wrong here
DeviceEvents is a general-purpose Advanced Hunting table that holds a heterogeneous mix of security events, including file creations, process injections, and other system-level telemetry, but it lacks the standardized network connection schema that DeviceNetworkEvents provides (RemoteIP, RemotePort, direction, etc.). Some network-related events might appear in DeviceEvents, but they are not consistently structured for querying by initiating process and endpoint, making this table unreliable for the analyst need. Additionally, many network connection events are only available in DeviceNetworkEvents, not duplicated into DeviceEvents.
- ✗
DeviceRegistryEvents
Why it's wrong here
DeviceRegistryEvents specifically tracks modifications to the Windows registry, including the registry key path, value name, and the process that performed the change, such as write operations to Run keys or service configurations. This table contains no network connection data whatsoever — no remote IPs, ports, or protocols — and its process information is tied to registry access, not to network communications. An analyst querying this table would see only hive activity and would find nothing related to the process network behavior.
Go deeper
Related to this question
Learn chapter
Exchange Mobile Device Policies (OWA)
Key term
XDR
XDR, or Extended Detection and Response, is a unified security platform that collects and correlates data across multiple security layers—endpoints, networks, servers, cloud workloads, and email—to improve threat detection and enable faster response.
Key term
Microsoft Defender XDR
Microsoft Defender XDR is a unified security platform that automatically correlates alerts from across an organization's endpoints, email, identities, and cloud apps to stop complex attacks.
About these practice questions
Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.