hardMultiple Choice
SC-200 Practice Question: A security analyst is investigating a…
A security analyst is investigating a sophisticated attack chain that started with a user clicking a link in a phishing email, which led to a drive-by download from a malicious website. The analyst wants to see the full list of URLs visited from the user's browser on the device. Which Advanced Hunting table contains this information?
⚠ Common exam trap
Candidates often confuse DeviceNetworkEvents (which shows network connections) with browser URL tracking, but DeviceNetworkEvents lacks the URL-level detail needed for web navigation analysis, while DeviceEvents is the dedicated table for browser activity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DeviceEvents
DeviceEvents in Microsoft Defender XDR captures browser-based activities, including URL visits, via the 'ActionType' field (e.g., 'BrowserUrlClicked' or 'BrowserUrlNavigation'). This table is specifically designed to log web navigation events from browsers like Microsoft Edge or Chrome, making it the correct source for the full list of URLs visited during the phishing attack chain.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
DeviceEvents
Why this is correct
DeviceEvents is the correct choice because the Advanced Hunting schema includes browser telemetry events such as UrlClicked, which explicitly record the full URL visited by the user. This table aggregates security-relevant events from Microsoft Defender for Endpoint components, including SmartScreen, and preserves the complete URL with its path and query string. For an investigation into a sophisticated attack that likely started with a user navigating to a malicious link, DeviceEvents provides the direct evidence of the exact visited resource, making it the most precise and source-of-truth table for URL-level browsing activity.
- ✗
DeviceNetworkEvents
Why it's wrong here
DeviceNetworkEvents is incorrect because it only captures the network-level flows, such as the remote IP address, remote port, protocol, and possibly the resolved DNS name, but it does not include the full URL path or HTTP request details. While a network event might show a connection to a malicious server, it lacks the browser context of which specific web page or URL parameter triggered that connection. An analyst would see that a device connected to 10.0.0.5 on port 443, but they would not see whether the user visited https://evil.com/payload or https://legitimate.com/clean, so this table cannot answer what exact URL was visited.
- ✗
DeviceProcessEvents
Why it's wrong here
DeviceProcessEvents is not the right table because it records process creation activity, including the image path, command line, parent process, and user account, but it does not contain any browser history or visited URL data. While the analyst might see a browser process like msedge.exe spawned with a command line, modern browsers do not place the visited URL into the process command line; and even if a URL appeared, it would be ephemeral and only for the initial process, not the sequence of pages visited. This table answers what executable ran and when, but it cannot provide the precise URL that the user typed or clicked in the browser.
- ✗
DeviceFileEvents
Why it's wrong here
DeviceFileEvents is inaccurate for this scenario because it focuses exclusively on file system events, such as when a file is created, modified, renamed, or deleted, tracking the file path, file name, folder, and initiating process. Browsing to a URL does not inherently generate a file creation or modification event, and the browser's history is stored internally in SQLite databases rather than being surfaced as discrete file events in this table. An analyst using this table might find a downloaded payload file after the attack, but it will not show the original URL that was visited to trigger the download, making it insufficient for determining the exact URL.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.