mediumMultiple Choice
SC-200 Practice Question: A security analyst suspects a user's device is…
A security analyst suspects a user's device is exfiltrating data via DNS queries to a known malicious domain. Which Advanced Hunting table should the analyst query to find DNS requests made from the device?
⚠ Common exam trap
A common mix-up: candidates confuse DeviceProcessEvents with network activity because processes initiate network connections, but DeviceProcessEvents only logs process creation details, not the actual network traffic or DNS queries.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DeviceNetworkEvents
DeviceNetworkEvents is the correct table because it contains network-level events, including DNS queries, from devices monitored by Microsoft Defender for Endpoint. The analyst needs to inspect DNS requests to identify exfiltration to a known malicious domain, and this table specifically logs the destination URL (including FQDNs) and the initiating process, making it the appropriate source for such queries.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
DeviceNetworkEvents
Why this is correct
This table in Microsoft 365 Defender (Advanced Hunting) captures network connections initiated by devices, including DNS queries when ActionType is DnsQuery. For exfiltration suspicion, DNS queries to known malicious domains or unusual patterns (e.g., high volume, TXT record payloads) can be detected. Also includes other network actions like ConnectionSuccess, so it's the primary table for network egress.
- ✗
DeviceProcessEvents
Why it's wrong here
This table logs process creation events, such as command-line arguments, parent processes, and file hashes. While a process could be a conduit for exfiltration (e.g., PowerShell script), the table doesn't record network connections or DNS query content. To see actual data leaving the device, you'd need to cross-reference process events with network events, but this table alone cannot reveal exfiltration.
- ✗
IdentityLogonEvents
Why it's wrong here
This table captures authentication events for users, including sign-ins and logon activity, primarily from Microsoft Entra ID (Azure AD). It does not contain endpoint-level DNS queries or network traffic. While compromised credentials might be used for exfiltration, the table itself lacks the network telemetry required to see data egress.
- ✗
EmailUrlInfo
Why it's wrong here
This table contains URL information from emails processed by Microsoft 365 Defender, such as links in email messages. It is not related to device network traffic or DNS queries. Exfiltration via email attachments or URLs would be visible in email events, but the question specifically mentions a device exfiltrating data, which points to endpoint network activity, not email content.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.