Courseiva

MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR

A security administrator wants to create a custom detection rule in Microsoft Defender XDR that alerts when a device initiates an outbound TCP connection to a known malicious IP address on a non-standard port (e.g., port 4444). Which advanced hunting table should be queried to find these network connections?

⚠ Common exam trap

A common mix-up: candidates confuse DeviceProcessEvents with network events because processes often initiate network connections, but DeviceProcessEvents does not contain network-level details like remote IP or port, leading to an incorrect choice.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

DeviceNetworkEvents

DeviceNetworkEvents is the correct table because it specifically captures network connection events, including outbound TCP connections to IP addresses and ports. This table contains fields like RemoteIP, RemotePort, and Protocol, making it ideal for detecting connections to known malicious IPs on non-standard ports such as 4444.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    DeviceNetworkEvents

    Why this is correct

    DeviceNetworkEvents is the advanced hunting table in Microsoft Defender XDR that records each network connection event on monitored endpoints, including LocalIP, RemoteIP, LocalPort, RemotePort, Protocol, and ActionType (e.g., ConnectionAttempt, ConnectionSuccess). For a custom detection rule that needs to flag suspicious outbound connectivity, this table is the authoritative source because every row represents an actual device-initiated or accepted network connection with the exact destination endpoint needed for threshold or indicator matching.

  • ✗

    DeviceProcessEvents

    Why it's wrong here

    DeviceProcessEvents is the wrong source because it captures process creation, modification, and termination events—command lines, executable hashes, parent-process relationships—but has no network-specific fields such as RemoteIP, RemotePort, or destination protocol. A custom detection rule built on this table would only see the initiating process, not the endpoint it contacted, so it cannot evaluate destination-based indicators like a known malicious C2 IP address. Process events are useful for behavioral reconnaissance, but they do not replace the network connection logs stored in DeviceNetworkEvents.

  • ✗

    EmailEvents

    Why it's wrong here

    EmailEvents belongs to the Microsoft 365 Defender email schema and contains message-level metadata—sender, recipients, subject, delivery action, and threat verdicts from Defender for Office 365. It is completely unrelated to endpoint network stack events; there are no columns for local/remote endpoint ports or protocol, and email transport data is collected by Exchange Online, not by the device sensor. Therefore, using EmailEvents as the query table for a device-network custom detection rule would be semantically invalid and would not return any DeviceNetworkEvents-style rows.

  • ✗

    IdentityLogonEvents

    Why it's wrong here

    IdentityLogonEvents logs authentication attempts and sign-in activity for user identities across Microsoft Entra ID and on-premises Active Directory, with fields such as AccountUpn, Application, LogonType, and the source IP of the authentication request. Although this table contains an IP address, that address identifies where the user's logon originated, not the remote destination a device connected to, and it lacks port/protocol data for endpoint connections. A custom detection rule seeking device network events would be querying an identity-based table, which cannot represent the outbound network conversations stored in DeviceNetworkEvents.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.