MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
You are a security administrator for Northwind Traders. You use Microsoft Defender XDR. You need to identify all devices that have communicated with a specific IP address associated with a known threat in the last 30 days. You want to use advanced hunting to find this information. Which table should you query?
⚠ Common exam trap
The trap here is assuming that DeviceEvents captures all network activity, when it primarily records process, file, and registry events.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DeviceNetworkEvents
Advanced hunting in Microsoft Defender XDR includes the DeviceNetworkEvents table, which logs network connections and associated remote IP addresses. To find devices that communicated with a specific IP, you query DeviceNetworkEvents, filter by the RemoteIP column for the threat IP, and restrict the Timestamp to the last 30 days. This yields the required device list.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
DeviceNetworkEvents
Why this is correct
The DeviceNetworkEvents table in advanced hunting contains information about network connections initiated by or involving devices, including remote IP addresses. Querying this table allows you to filter for the specific IP address and the time range, returning the devices that communicated with it. This directly answers the requirement.
- ✗
DeviceFileEvents
Why it's wrong here
DeviceFileEvents tracks file creation, modification, and deletion activities on devices. It does not include network connection data. Querying this table would not provide any information about communications with an IP address, so it fails to meet the requirement.
- ✗
DeviceEvents
Why it's wrong here
DeviceEvents contains various event types such as process creation, file creation, and registry modifications, but it does not focus on network connections. While some network-related events might appear, it is not the primary table for tracking communications with a specific IP address. Using it would likely miss relevant network connections.
- ✗
DeviceLogonEvents
Why it's wrong here
DeviceLogonEvents records logon and authentication events on devices, including interactive and remote logons. It does not contain information about network connections to external IP addresses. This table is not suitable for identifying devices that communicated with a specific IP address.
Go deeper
Related to this question
Learn chapter
Exchange Mobile Device Policies (OWA)
Key term
Threat
A threat is any potential danger that could harm a computer system, network, or data, whether from a malicious hacker, a natural disaster, or an accidental mistake.
Key term
Microsoft Defender XDR
Microsoft Defender XDR is a unified security platform that automatically correlates alerts from across an organization's endpoints, email, identities, and cloud apps to stop complex attacks.
About these practice questions
One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.