SC-200 Perform threat hunting Practice Question
A threat hunter is investigating a potential data exfiltration via DNS tunneling. Which Microsoft Defender XDR advanced hunting table should the analyst primarily use to examine DNS queries from endpoints?
⚠ Common exam trap
The trap is assuming that any table with 'Network' in the name contains DNS data, or defaulting to AlertInfo because the scenario mentions an investigation. The exam tests whether you know that raw endpoint DNS query telemetry lives in DeviceEvents (ActionType == 'DnsQuery'), not DeviceNetworkEvents.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DeviceEvents
In Microsoft Defender XDR advanced hunting, raw DNS query telemetry from endpoints is recorded in the DeviceEvents table, where events with ActionType equal to 'DnsQuery' include the queried domain (in AdditionalFields) and the initiating process. DeviceNetworkEvents records network connection events (RemoteIP, RemoteUrl, RemotePort, etc.) and does not contain a DnsQuery field or per-query DNS resolution data. Therefore, to examine DNS queries from endpoints for suspected DNS tunneling, the analyst should use DeviceEvents filtered on ActionType == 'DnsQuery'.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
DeviceEvents
Why this is correct
DeviceNetworkEvents records network connection events from onboarded endpoints, including DNS query details and remote addresses. This makes it the primary table for spotting DNS tunnelling patterns such as high-volume or encoded queries to suspicious domains.
- ✗
IdentityLogonEvents
Why it's wrong here
IdentityLogonEvents logs authentication events and is not relevant to DNS queries.
- ✗
AlertInfo
Why it's wrong here
AlertInfo provides alert metadata, not raw DNS queries, so it is incorrect.
- ✗
EmailEvents
Why it's wrong here
EmailEvents is for email-related events and does not contain endpoint DNS queries.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.