Courseiva
Perform threat hunting →easyMultiple Choice

SC-200 Perform threat hunting Practice Question

A threat hunter is investigating a potential data exfiltration via DNS tunneling. Which Microsoft Defender XDR advanced hunting table should the analyst primarily use to examine DNS queries from endpoints?

⚠ Common exam trap

The trap is assuming that any table with 'Network' in the name contains DNS data, or defaulting to AlertInfo because the scenario mentions an investigation. The exam tests whether you know that raw endpoint DNS query telemetry lives in DeviceEvents (ActionType == 'DnsQuery'), not DeviceNetworkEvents.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

DeviceEvents

In Microsoft Defender XDR advanced hunting, raw DNS query telemetry from endpoints is recorded in the DeviceEvents table, where events with ActionType equal to 'DnsQuery' include the queried domain (in AdditionalFields) and the initiating process. DeviceNetworkEvents records network connection events (RemoteIP, RemoteUrl, RemotePort, etc.) and does not contain a DnsQuery field or per-query DNS resolution data. Therefore, to examine DNS queries from endpoints for suspected DNS tunneling, the analyst should use DeviceEvents filtered on ActionType == 'DnsQuery'.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    DeviceEvents

    Why this is correct

    DeviceNetworkEvents records network connection events from onboarded endpoints, including DNS query details and remote addresses. This makes it the primary table for spotting DNS tunnelling patterns such as high-volume or encoded queries to suspicious domains.

  • ✗

    IdentityLogonEvents

    Why it's wrong here

    IdentityLogonEvents logs authentication events and is not relevant to DNS queries.

  • ✗

    AlertInfo

    Why it's wrong here

    AlertInfo provides alert metadata, not raw DNS queries, so it is incorrect.

  • ✗

    EmailEvents

    Why it's wrong here

    EmailEvents is for email-related events and does not contain endpoint DNS queries.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.