mediumMultiple Choice
SC-200 Practice Question: A security analyst is investigating lateral…
A security analyst is investigating lateral movement in Microsoft 365 Defender. They have identified a compromised device (DeviceA) and want to find all other devices that have been accessed from DeviceA via RDP in the last 24 hours. Which advanced hunting table contains RDP connection events?
⚠ Common exam trap
Many exam-takers confuse 'RDP connection events' with authentication events (DeviceLogonEvents) or process creation (DeviceProcessEvents), but the question specifically asks for the table containing the network connection data, not the logon or process launch.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DeviceNetworkEvents
DeviceNetworkEvents is the correct table because it captures network-level connection events, including outbound RDP (TCP port 3389) connections. When a compromised device initiates an RDP session to another device, the network event is logged here, allowing the analyst to trace lateral movement by filtering for `RemotePort == 3389` and `RemoteIP` of the target.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
DeviceNetworkEvents
Why this is correct
DeviceNetworkEvents is the correct source because it records every network connection attempt and established session at the device level, including the remote IP address, remote port (e.g., 3389 for RDP), protocol, and the process that initiated the connection. This table directly surfaces the outbound or inbound network flows that constitute lateral movement over RDP, enabling an analyst to trace which endpoint connected to which target and when. Unlike other event tables, DeviceNetworkEvents preserves both direction and destination details, which are essential for reconstructing lateral movement paths.
- ✗
DeviceLogonEvents
Why it's wrong here
DeviceLogonEvents captures successful and failed authentication events on a device, such as a user logging on via RDP, along with the logon type and source IP address. However, it does not record the network-level connection itself—there is no destination port, protocol, or bidirectional flow information. While an RDP logon might appear here, the table lacks the granular network flow details needed to definitively map the network connection that enabled the lateral movement, making it secondary to DeviceNetworkEvents for this investigation.
- ✗
DeviceProcessEvents
Why it's wrong here
DeviceProcessEvents logs process creation activity, including command-line arguments, executable paths, and parent-child process relationships. During lateral movement, an attacker might use a tool like PsExec or powershell.exe, and the resulting remote process creation would be visible in this table; however, the network connection that scoped the destination and port (e.g., SMB over 445 or RDP over 3389) is not part of this table. Thus, DeviceProcessEvents provides only a corroborating artifact, not the definitive network connection evidence needed to identify the lateral movement pathway.
- ✗
IdentityLogonEvents
Why it's wrong here
IdentityLogonEvents is an identity-centric table that tracks authentication events to Microsoft Entra ID (Azure AD), such as sign-ins to cloud applications, rather than endpoint-level network connections. It does not contain device-to-device TCP/IP flow records, remote ports, or processes, and it is unrelated to on-premises RDP lateral movement. Analysts investigating lateral movement between endpoints should rely on device-level telemetry like DeviceNetworkEvents, not cloud identity sign-in logs.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.