Courseiva

MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR

You are a security administrator for Northwind Traders. You use Microsoft Defender XDR. You need to identify all devices that have communicated with a specific IP address associated with a known threat in the last 30 days. You want to use advanced hunting to find this information. Which table should you query?

⚠ Common exam trap

The trap here is assuming that DeviceEvents captures all network activity, when it primarily records process, file, and registry events.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

DeviceNetworkEvents

Advanced hunting in Microsoft Defender XDR includes the DeviceNetworkEvents table, which logs network connections and associated remote IP addresses. To find devices that communicated with a specific IP, you query DeviceNetworkEvents, filter by the RemoteIP column for the threat IP, and restrict the Timestamp to the last 30 days. This yields the required device list.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    DeviceNetworkEvents

    Why this is correct

    The DeviceNetworkEvents table in advanced hunting contains information about network connections initiated by or involving devices, including remote IP addresses. Querying this table allows you to filter for the specific IP address and the time range, returning the devices that communicated with it. This directly answers the requirement.

  • ✗

    DeviceFileEvents

    Why it's wrong here

    DeviceFileEvents tracks file creation, modification, and deletion activities on devices. It does not include network connection data. Querying this table would not provide any information about communications with an IP address, so it fails to meet the requirement.

  • ✗

    DeviceEvents

    Why it's wrong here

    DeviceEvents contains various event types such as process creation, file creation, and registry modifications, but it does not focus on network connections. While some network-related events might appear, it is not the primary table for tracking communications with a specific IP address. Using it would likely miss relevant network connections.

  • ✗

    DeviceLogonEvents

    Why it's wrong here

    DeviceLogonEvents records logon and authentication events on devices, including interactive and remote logons. It does not contain information about network connections to external IP addresses. This table is not suitable for identifying devices that communicated with a specific IP address.

About these practice questions

One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.