SC-200 Perform threat hunting Practice Question
A threat hunter wants to identify all devices that have communicated with a known malicious IP address in the last 7 days. Which table in Microsoft Defender for Endpoint advanced hunting should be queried?
⚠ Common exam trap
SC-200 often tests knowledge of the advanced hunting schema, and candidates may confuse network events with process or file events, leading to incorrect table selection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DeviceNetworkEvents
The DeviceNetworkEvents table in Microsoft Defender for Endpoint advanced hunting contains information about network connections, including remote IP addresses and ports. To identify devices that communicated with a specific malicious IP, querying this table for the RemoteIP field is the correct approach. It captures both inbound and outbound network traffic events.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
DeviceFileEvents
Why it's wrong here
DeviceFileEvents tracks file-oriented operations such as creation, modification, and deletion on the endpoint. When a device communicates with a malicious IP, that connection is a network-layer event, not a file-system change, so this table would return no valid results for the hunt. File evidence may support an investigation, but it cannot identify the communication itself.
- ✓
DeviceNetworkEvents
Why this is correct
DeviceNetworkEvents is the Advanced Hunting table that stores network connection activity initiated by processes, including source and destination IP addresses, remote ports, protocols, and connection metadata. A threat hunter can query this table with a known-bad IP or domain to list every device that established such communication. This makes it the direct and authoritative source for identifying compromised or suspicious endpoints.
- ✗
DeviceProcessEvents
Why it's wrong here
DeviceProcessEvents captures process creation events, such as executable start time, command-line arguments, and parent-child relationships. Although a process may be responsible for initiating network traffic, this table does not record the destination IPs or network endpoints that were contacted. To tie a process to a specific malicious destination, you must join DeviceProcessEvents with DeviceNetworkEvents.
- ✗
DeviceRegistryEvents
Why it's wrong here
DeviceRegistryEvents logs changes to the Windows registry, including key creation, value modifications, and persistence mechanisms. Network connections are not stored in the registry and are outside the scope of this table, so querying it would fail to reveal any communications with a threat actor's infrastructure. Registry data might help in later forensic analysis, but it is not how you enumerate communicating devices.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.