MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
You are a security administrator for a company that uses Microsoft Defender XDR. The security team wants to identify all devices that have communicated with a specific malicious IP address over the past 30 days. They need to run an advanced hunting query. Which table should they query?
⚠ Common exam trap
Watch out — candidates often confuse general device event tables with the specialized network events table, leading to incomplete or inaccurate query results.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DeviceNetworkEvents
DeviceNetworkEvents is the dedicated table for network connection events in Microsoft Defender XDR advanced hunting. It includes fields like RemoteIP, LocalIP, and RemotePort, enabling precise filtering for communications with a specific malicious IP address.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
DeviceEvents
Why it's wrong here
DeviceEvents is a general table that includes various event types, including some network-related events, but it is not the primary table for network connection details. DeviceNetworkEvents is specifically designed for network connections and includes RemoteIP, making it more precise for this query.
- ✗
DeviceProcessEvents
Why it's wrong here
DeviceProcessEvents contains process creation and termination events, not network connections. While it may show processes that initiated network activity, it does not directly record remote IP addresses. Therefore, it cannot be used to identify devices that communicated with a specific IP address over time.
- ✓
DeviceNetworkEvents
Why this is correct
DeviceNetworkEvents contains network connection events from devices, including remote IP addresses and ports. Querying this table allows you to filter by RemoteIP and time range to find devices that communicated with the malicious IP. This is the correct table for network communication history in Microsoft Defender XDR advanced hunting.
- ✗
DeviceFileEvents
Why it's wrong here
DeviceFileEvents records file creation, modification, and deletion events. It does not contain network connection information such as remote IP addresses. Using this table would not help identify devices communicating with a malicious IP, as it lacks the necessary network telemetry.
Go deeper
Related to this question
Learn chapter
Endpoint DLP for Windows Devices
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
XDR
XDR, or Extended Detection and Response, is a unified security platform that collects and correlates data across multiple security layers—endpoints, networks, servers, cloud workloads, and email—to improve threat detection and enable faster response.
About these practice questions
Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.