Courseiva

MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR

You are a security administrator for a company that uses Microsoft Defender XDR. The security team wants to identify all devices that have communicated with a specific malicious IP address over the past 30 days. They need to run an advanced hunting query. Which table should they query?

⚠ Common exam trap

Watch out — candidates often confuse general device event tables with the specialized network events table, leading to incomplete or inaccurate query results.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

DeviceNetworkEvents

DeviceNetworkEvents is the dedicated table for network connection events in Microsoft Defender XDR advanced hunting. It includes fields like RemoteIP, LocalIP, and RemotePort, enabling precise filtering for communications with a specific malicious IP address.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    DeviceEvents

    Why it's wrong here

    DeviceEvents is a general table that includes various event types, including some network-related events, but it is not the primary table for network connection details. DeviceNetworkEvents is specifically designed for network connections and includes RemoteIP, making it more precise for this query.

  • ✗

    DeviceProcessEvents

    Why it's wrong here

    DeviceProcessEvents contains process creation and termination events, not network connections. While it may show processes that initiated network activity, it does not directly record remote IP addresses. Therefore, it cannot be used to identify devices that communicated with a specific IP address over time.

  • ✓

    DeviceNetworkEvents

    Why this is correct

    DeviceNetworkEvents contains network connection events from devices, including remote IP addresses and ports. Querying this table allows you to filter by RemoteIP and time range to find devices that communicated with the malicious IP. This is the correct table for network communication history in Microsoft Defender XDR advanced hunting.

  • ✗

    DeviceFileEvents

    Why it's wrong here

    DeviceFileEvents records file creation, modification, and deletion events. It does not contain network connection information such as remote IP addresses. Using this table would not help identify devices communicating with a malicious IP, as it lacks the necessary network telemetry.

About these practice questions

Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.