You are a security administrator for a company that uses Microsoft Defender XDR. The security team wants to identify all devices that have communicated with a specific malicious IP address over the past 30 days. They need to run an advanced hunting query. Which table should they query?
DeviceNetworkEvents contains network connection events from devices, including remote IP addresses and ports. Querying this table allows you to filter by RemoteIP and time range to find devices that communicated with the malicious IP. This is the correct table for network communication history in Microsoft Defender XDR advanced hunting.
Why this answer
DeviceNetworkEvents is the dedicated table for network connection events in Microsoft Defender XDR advanced hunting. It includes fields like RemoteIP, LocalIP, and RemotePort, enabling precise filtering for communications with a specific malicious IP address.
Exam trap
The trap here is confusing general device event tables with the specialized network events table, leading to incomplete or inaccurate query results.