Courseiva

MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR

A security analyst needs to search for devices that have been communicating with a known malicious command-and-control server over the past 7 days. The analyst wants to identify the process that initiated the connection. Which advanced hunting query would be most efficient?

⚠ Common exam trap

Many exam-takers choose Option C thinking a join is necessary to get process details, but DeviceNetworkEvents already includes the initiating process name, making the join redundant and inefficient.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

DeviceNetworkEvents | where RemoteIP == 'malicious IP' and Timestamp > ago(7d) | project DeviceName, InitiatingProcessFileName, Timestamp

DeviceNetworkEvents contains network connection data including the remote IP and the initiating process details. Filtering by RemoteIP and Timestamp directly retrieves the required information without unnecessary joins or subqueries, making it the most efficient query for identifying the process that initiated the connection to a known malicious C2 server.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    DeviceNetworkEvents | where RemoteIP == 'malicious IP' and Timestamp > ago(7d) | project DeviceName, InitiatingProcessFileName, Timestamp

    Why this is correct

    This is the correct query because DeviceNetworkEvents is the Microsoft 365 Defender table that logs outbound network connections, and it natively includes the InitiatingProcessFileName field. Filtering on RemoteIP and a 7-day Timestamp window directly narrows to the relevant events, then projecting the three required columns gives the answer without any additional joins or subqueries.

  • ✗

    DeviceProcessEvents | where ProcessId in (select ProcessId from DeviceNetworkEvents where RemoteIP == 'malicious IP' and Timestamp > ago(7d)) | project DeviceName, ProcessFileName, Timestamp

    Why it's wrong here

    This query is incorrect because it uses a subquery to retrieve ProcessIds from DeviceNetworkEvents and then looks those up in DeviceProcessEvents, introducing unnecessary complexity and potential performance overhead. More critically, ProcessId is only unique per process on a given device at a given time; without also matching DeviceId and Timestamp, the IN clause can incorrectly match an unrelated process that happens to reuse the same ProcessId. The directly available InitiatingProcessFileName in DeviceNetworkEvents makes this extra step redundant.

  • ✗

    DeviceNetworkEvents | where Timestamp > ago(7d) | join DeviceProcessEvents on ProcessId | where RemoteIP == 'malicious IP' | project DeviceName, ProcessFileName, Timestamp

    Why it's wrong here

    Joining DeviceNetworkEvents to DeviceProcessEvents on ProcessId alone is flawed because the join key is not sufficiently unique across devices and time; without DeviceId and a time window, it can produce incorrect matches and duplicate rows. Additionally, DeviceNetworkEvents already contains the initiating process filename, so the join is architecturally unnecessary. This approach also requires filtering after the join, causing the query to process far more data than needed.

  • ✗

    IdentityLogonEvents | where IPAddress == 'malicious IP' | project DeviceName, Timestamp

    Why it's wrong here

    IdentityLogonEvents is designed to track user authentication and logon activities, not outbound network connections to an IP address, so it cannot answer a question about devices communicating with a malicious IP. The schema lacks a RemoteIP field and process information such as InitiatingProcessFileName; instead it uses IPAddress only for the logon source. DeviceNetworkEvents is the appropriate table because it records network-level events with the initiating process.

About these practice questions

This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.