MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
A security administrator wants to create a custom detection rule in Microsoft Defender XDR that alerts when a device initiates an outbound TCP connection to a known malicious IP address on a non-standard port (e.g., port 4444). Which advanced hunting table should be queried to find these network connections?
⚠ Common exam trap
A common mix-up: candidates confuse DeviceProcessEvents with network events because processes often initiate network connections, but DeviceProcessEvents does not contain network-level details like remote IP or port, leading to an incorrect choice.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DeviceNetworkEvents
DeviceNetworkEvents is the correct table because it specifically captures network connection events, including outbound TCP connections to IP addresses and ports. This table contains fields like RemoteIP, RemotePort, and Protocol, making it ideal for detecting connections to known malicious IPs on non-standard ports such as 4444.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
DeviceNetworkEvents
Why this is correct
DeviceNetworkEvents is the advanced hunting table in Microsoft Defender XDR that records each network connection event on monitored endpoints, including LocalIP, RemoteIP, LocalPort, RemotePort, Protocol, and ActionType (e.g., ConnectionAttempt, ConnectionSuccess). For a custom detection rule that needs to flag suspicious outbound connectivity, this table is the authoritative source because every row represents an actual device-initiated or accepted network connection with the exact destination endpoint needed for threshold or indicator matching.
- ✗
DeviceProcessEvents
Why it's wrong here
DeviceProcessEvents is the wrong source because it captures process creation, modification, and termination events—command lines, executable hashes, parent-process relationships—but has no network-specific fields such as RemoteIP, RemotePort, or destination protocol. A custom detection rule built on this table would only see the initiating process, not the endpoint it contacted, so it cannot evaluate destination-based indicators like a known malicious C2 IP address. Process events are useful for behavioral reconnaissance, but they do not replace the network connection logs stored in DeviceNetworkEvents.
- ✗
EmailEvents
Why it's wrong here
EmailEvents belongs to the Microsoft 365 Defender email schema and contains message-level metadata—sender, recipients, subject, delivery action, and threat verdicts from Defender for Office 365. It is completely unrelated to endpoint network stack events; there are no columns for local/remote endpoint ports or protocol, and email transport data is collected by Exchange Online, not by the device sensor. Therefore, using EmailEvents as the query table for a device-network custom detection rule would be semantically invalid and would not return any DeviceNetworkEvents-style rows.
- ✗
IdentityLogonEvents
Why it's wrong here
IdentityLogonEvents logs authentication attempts and sign-in activity for user identities across Microsoft Entra ID and on-premises Active Directory, with fields such as AccountUpn, Application, LogonType, and the source IP of the authentication request. Although this table contains an IP address, that address identifies where the user's logon originated, not the remote destination a device connected to, and it lacks port/protocol data for endpoint connections. A custom detection rule seeking device network events would be querying an identity-based table, which cannot represent the outbound network conversations stored in DeviceNetworkEvents.
Visual reference
Go deeper
Related to this question
Learn chapter
Exchange Mobile Device Policies (OWA)
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Microsoft Defender XDR
Microsoft Defender XDR is a unified security platform that automatically correlates alerts from across an organization's endpoints, email, identities, and cloud apps to stop complex attacks.
About these practice questions
Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.