Courseiva

MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR

A security analyst wants to create a custom detection rule in Microsoft Defender XDR that triggers when a device establishes a network connection to an IP address that has been recently observed in threat intelligence feeds as a new, malicious command-and-control server. The rule should analyze network communication events. Which advanced hunting table should be the primary data source for the Kusto Query Language (KQL) query?

⚠ Common exam trap

Microsoft often tests the confusion between process-level and network-level tables, leading candidates to choose DeviceProcessEvents because they mistakenly think process creation is the primary indicator of malicious network activity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

DeviceNetworkEvents

DeviceNetworkEvents is the correct primary data source because it captures network connection events, including source and destination IP addresses, ports, and protocols. To detect a device connecting to a newly observed malicious command-and-control server, the KQL query must analyze network communication events, which are stored exclusively in this table.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    DeviceProcessEvents

    Why it's wrong here

    DeviceProcessEvents logs process creation and invocation events, such as executable names, command lines, and parent-child process relationships. It does not contain fields for network source or destination IP addresses or ports, so it cannot be directly queried to detect connections to a specific suspicious IP. While you might use it to identify a process that later makes a network connection, that requires joining with a network event table, making it unsuitable as the sole data source for this custom detection rule.

  • ✓

    DeviceNetworkEvents

    Why this is correct

    DeviceNetworkEvents is the correct table because it records actual network connection events, including TCP, UDP, and ICMP traffic, with fields such as RemoteIP, RemotePort, LocalIP, LocalPort, and Protocol. A custom detection rule can filter directly on RemoteIP to flag connections to a known malicious IP address. It also provides DeviceId and other machine identifiers, enabling correlation with process and user context. This table is specifically designed for hunting network-based threats, making it the appropriate choice for IP-based detection rules.

  • ✗

    EmailEvents

    Why it's wrong here

    EmailEvents captures email metadata and delivery details, including sender and recipient addresses, subject, and attachment information, but it does not record device-level network connections to arbitrary IP addresses. While email headers may contain an originating IP address, that is a property of the message transport, not the outbound TCP/IP connection from a monitored device. Therefore, this table cannot answer the question of which devices on your network are connecting to a given IP and is irrelevant for a device network connection detection rule.

  • ✗

    AlertEvidence

    Why it's wrong here

    AlertEvidence contains entities and contextual data associated with existing security alerts, such as file paths, users, IP addresses, and process names that were involved in an alert. It is populated only after an alert is generated, and its records are snapshots of evidence rather than a continuous, raw event stream of network connections. A custom detection rule requires a schema with one row per network event, so using AlertEvidence would fail to detect new connections in real time and would not provide the granular per-connection data needed for IP-based detection.

About these practice questions

This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.