Courseiva

MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR

Your organization uses Microsoft Defender for Endpoint. You need to configure advanced hunting to query device information. Which TWO tables contain device-related data?

⚠ Common exam trap

Test-takers frequently confuse tables that contain device identifiers (like IdentityLogonEvents or AlertInfo) with tables that store actual device-related data, leading them to select tables that only reference devices indirectly rather than containing device properties.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

DeviceInfo

DeviceInfo is correct because it is the primary table in Microsoft Defender for Endpoint advanced hunting that stores comprehensive device metadata, including OS version, device name, and sensor health. This table is essential for querying device-related information such as device inventory, onboarding status, and configuration details.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AlertInfo

    Why it's wrong here

    AlertInfo is an Advanced Hunting table in Microsoft 365 Defender that stores metadata for every alert, including alert ID, title, severity, and detection source. While this table is useful for investigating incidents and correlating with other events, it does not contain device-level inventory data such as OS version, device name, or hardware details. Therefore, it cannot be used to identify devices based on operating system characteristics.

  • ✗

    EmailEvents

    Why it's wrong here

    EmailEvents is an Advanced Hunting schema designed to track email transport and processing events within Exchange Online, capturing details like sender, recipient, subject, and delivery status. This table is focused on mail flow and phishing analysis, not on the endpoint devices that access email. It lacks the necessary device identifiers and OS attributes, making it inappropriate for any query about device inventory.

  • ✗

    IdentityLogonEvents

    Why it's wrong here

    IdentityLogonEvents records authentication and sign-in activities, such as successful or failed logons, the account used, the IP address from which the logon originated, and the authentication method. This table is instrumental for detecting brute-force or compromised identities, but it does not provide detailed device configuration like OS build or device name, as those are stored in the device information schema.

  • ✓

    DeviceInfo

    Why this is correct

    DeviceInfo is the core table in Microsoft Defender for Endpoint's Advanced Hunting that maintains a comprehensive inventory of all onboarded devices, including device ID, device name, OS platform, OS version, and last seen timestamp. It is the authoritative source for answering questions like 'which devices run Windows 11' or 'what OS versions are present.' By querying DeviceInfo and filtering on the OSVersion column, you can quickly retrieve the required device details.

  • ✓

    DeviceTvmInfoGathering

    Why this is correct

    DeviceTvmInfoGathering is a specialized table designed for Threat and Vulnerability Management, providing per-device telemetry about software inventory, vulnerability findings, and security configuration assessments. It does include a device identifier for correlation, but its primary content is vulnerability data, not a full inventory of OS version or general device attributes. Using it for basic OS queries would be inefficient and may exclude devices not fully assessed by TVM.

About these practice questions

Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.