Courseiva
hardMultiple Choice

SC-200 DeviceLogonEvents Practice Question

A security analyst uses advanced hunting in Microsoft 365 Defender to investigate a potential lateral movement attack. The analyst suspects that an attacker used stolen credentials to authenticate to multiple workstations via RDP. Which KQL query would return a list of devices where a single user account (user@contoso.com) had successful interactive logons on more than 5 distinct devices within a 10-minute window?

⚠ Common exam trap

Many exam-takers confuse DeviceLogonEvents with IdentityLogonEvents or DeviceNetworkEvents, mistakenly thinking network events or identity provider logs can reveal device-level interactive logon patterns, but only DeviceLogonEvents contains the necessary fields (AccountUpn, LogonType, DeviceName) for this specific lateral movement detection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

DeviceLogonEvents | where AccountUpn == 'user@contoso.com' and LogonType == 'Interactive' | summarize dcount(DeviceName) by bin(Timestamp, 10m) | where dcount_DeviceName > 5

DeviceLogonEvents is the Microsoft 365 Defender table that captures logon events on devices, including RDP interactive logons. The query filters for the specific user account and interactive logon type, then uses summarize with dcount(DeviceName) by bin(Timestamp, 10m) to count distinct devices within each 10-minute window, and finally filters for windows where the distinct device count exceeds 5, which matches the lateral movement scenario.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    DeviceNetworkEvents | where RemoteIP == 'user@contoso.com' | summarize dcount(DeviceName) by bin(Timestamp, 10m) | where dcount_DeviceName > 5

    Why it's wrong here

    DeviceNetworkEvents records network connections and has no AccountUpn or LogonType fields, so filtering RemoteIP against a UPN returns nothing. It is tempting because it is the table for connection data, and would be correct for querying remote IP addresses and ports, not interactive logon attribution.

  • ✗

    IdentityLogonEvents | where AccountUpn == 'user@contoso.com' and LogonType == 'Interactive' | summarize dcount(DeviceName) by bin(Timestamp, 10m) | where dcount_DeviceName > 5

    Why it's wrong here

    IdentityLogonEvents covers Microsoft Entra ID, Active Directory and cloud authentication events, but does not record RDP interactive logons on individual workstations; DeviceLogonEvents does. It is tempting because it is the identity-focused logon table, and would be correct for investigating suspicious cloud or directory sign-ins.

  • ✓

    DeviceLogonEvents | where AccountUpn == 'user@contoso.com' and LogonType == 'Interactive' | summarize dcount(DeviceName) by bin(Timestamp, 10m) | where dcount_DeviceName > 5

    Why this is correct

    DeviceLogonEvents records successful interactive logons with AccountUpn and DeviceName. Filtering by that account and LogonType, then summarising distinct devices per 10-minute bin, surfaces any window where one account touched more than five workstations, matching the lateral-movement hypothesis.

  • ✗

    DeviceLogonEvents | where AccountUpn == 'user@contoso.com' | summarize count() by DeviceName, bin(Timestamp, 10m) | where count_ > 5

    Why it's wrong here

    This summarizes by DeviceName and time, giving count per device. It does not count the number of distinct devices per time window. The condition would filter for a single device with many logons, not multiple devices.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.