MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
A security analyst wants to create a custom detection rule in Microsoft Defender XDR that triggers when a device establishes a network connection to an IP address that has been recently observed in threat intelligence feeds as a new, malicious command-and-control server. The rule should analyze network communication events. Which advanced hunting table should be the primary data source for the Kusto Query Language (KQL) query?
⚠ Common exam trap
Microsoft often tests the confusion between process-level and network-level tables, leading candidates to choose DeviceProcessEvents because they mistakenly think process creation is the primary indicator of malicious network activity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DeviceNetworkEvents
DeviceNetworkEvents is the correct primary data source because it captures network connection events, including source and destination IP addresses, ports, and protocols. To detect a device connecting to a newly observed malicious command-and-control server, the KQL query must analyze network communication events, which are stored exclusively in this table.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
DeviceProcessEvents
Why it's wrong here
DeviceProcessEvents logs process creation and invocation events, such as executable names, command lines, and parent-child process relationships. It does not contain fields for network source or destination IP addresses or ports, so it cannot be directly queried to detect connections to a specific suspicious IP. While you might use it to identify a process that later makes a network connection, that requires joining with a network event table, making it unsuitable as the sole data source for this custom detection rule.
- ✓
DeviceNetworkEvents
Why this is correct
DeviceNetworkEvents is the correct table because it records actual network connection events, including TCP, UDP, and ICMP traffic, with fields such as RemoteIP, RemotePort, LocalIP, LocalPort, and Protocol. A custom detection rule can filter directly on RemoteIP to flag connections to a known malicious IP address. It also provides DeviceId and other machine identifiers, enabling correlation with process and user context. This table is specifically designed for hunting network-based threats, making it the appropriate choice for IP-based detection rules.
- ✗
EmailEvents
Why it's wrong here
EmailEvents captures email metadata and delivery details, including sender and recipient addresses, subject, and attachment information, but it does not record device-level network connections to arbitrary IP addresses. While email headers may contain an originating IP address, that is a property of the message transport, not the outbound TCP/IP connection from a monitored device. Therefore, this table cannot answer the question of which devices on your network are connecting to a given IP and is irrelevant for a device network connection detection rule.
- ✗
AlertEvidence
Why it's wrong here
AlertEvidence contains entities and contextual data associated with existing security alerts, such as file paths, users, IP addresses, and process names that were involved in an alert. It is populated only after an alert is generated, and its records are snapshots of evidence rather than a continuous, raw event stream of network connections. A custom detection rule requires a schema with one row per network event, so using AlertEvidence would fail to detect new connections in real time and would not provide the granular per-connection data needed for IP-based detection.
Go deeper
Related to this question
Learn chapter
Exchange Mobile Device Policies (OWA)
Key term
Threat
A threat is any potential danger that could harm a computer system, network, or data, whether from a malicious hacker, a natural disaster, or an accidental mistake.
Key term
Threat intelligence
Threat intelligence is evidence-based knowledge about existing or emerging cyber threats that helps organizations defend against attacks.
About these practice questions
This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.