MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR
Your organization uses Microsoft Defender for Endpoint. You need to configure advanced hunting to query device information. Which TWO tables contain device-related data?
⚠ Common exam trap
Test-takers frequently confuse tables that contain device identifiers (like IdentityLogonEvents or AlertInfo) with tables that store actual device-related data, leading them to select tables that only reference devices indirectly rather than containing device properties.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DeviceInfo
DeviceInfo is correct because it is the primary table in Microsoft Defender for Endpoint advanced hunting that stores comprehensive device metadata, including OS version, device name, and sensor health. This table is essential for querying device-related information such as device inventory, onboarding status, and configuration details.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AlertInfo
Why it's wrong here
AlertInfo is an Advanced Hunting table in Microsoft 365 Defender that stores metadata for every alert, including alert ID, title, severity, and detection source. While this table is useful for investigating incidents and correlating with other events, it does not contain device-level inventory data such as OS version, device name, or hardware details. Therefore, it cannot be used to identify devices based on operating system characteristics.
- ✗
EmailEvents
Why it's wrong here
EmailEvents is an Advanced Hunting schema designed to track email transport and processing events within Exchange Online, capturing details like sender, recipient, subject, and delivery status. This table is focused on mail flow and phishing analysis, not on the endpoint devices that access email. It lacks the necessary device identifiers and OS attributes, making it inappropriate for any query about device inventory.
- ✗
IdentityLogonEvents
Why it's wrong here
IdentityLogonEvents records authentication and sign-in activities, such as successful or failed logons, the account used, the IP address from which the logon originated, and the authentication method. This table is instrumental for detecting brute-force or compromised identities, but it does not provide detailed device configuration like OS build or device name, as those are stored in the device information schema.
- ✓
DeviceInfo
Why this is correct
DeviceInfo is the core table in Microsoft Defender for Endpoint's Advanced Hunting that maintains a comprehensive inventory of all onboarded devices, including device ID, device name, OS platform, OS version, and last seen timestamp. It is the authoritative source for answering questions like 'which devices run Windows 11' or 'what OS versions are present.' By querying DeviceInfo and filtering on the OSVersion column, you can quickly retrieve the required device details.
- ✓
DeviceTvmInfoGathering
Why this is correct
DeviceTvmInfoGathering is a specialized table designed for Threat and Vulnerability Management, providing per-device telemetry about software inventory, vulnerability findings, and security configuration assessments. It does include a device identifier for correlation, but its primary content is vulnerability data, not a full inventory of OS version or general device attributes. Using it for basic OS queries would be inefficient and may exclude devices not fully assessed by TVM.
Go deeper
Related to this question
About these practice questions
Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.