Courseiva
Perform threat hunting →easyMultiple Choice

SC-200 Perform threat hunting Practice Question

A threat hunter wants to identify all devices that have communicated with a known malicious IP address in the last 7 days. Which table in Microsoft Defender for Endpoint advanced hunting should be queried?

⚠ Common exam trap

SC-200 often tests knowledge of the advanced hunting schema, and candidates may confuse network events with process or file events, leading to incorrect table selection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

DeviceNetworkEvents

The DeviceNetworkEvents table in Microsoft Defender for Endpoint advanced hunting contains information about network connections, including remote IP addresses and ports. To identify devices that communicated with a specific malicious IP, querying this table for the RemoteIP field is the correct approach. It captures both inbound and outbound network traffic events.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    DeviceFileEvents

    Why it's wrong here

    DeviceFileEvents tracks file-oriented operations such as creation, modification, and deletion on the endpoint. When a device communicates with a malicious IP, that connection is a network-layer event, not a file-system change, so this table would return no valid results for the hunt. File evidence may support an investigation, but it cannot identify the communication itself.

  • ✓

    DeviceNetworkEvents

    Why this is correct

    DeviceNetworkEvents is the Advanced Hunting table that stores network connection activity initiated by processes, including source and destination IP addresses, remote ports, protocols, and connection metadata. A threat hunter can query this table with a known-bad IP or domain to list every device that established such communication. This makes it the direct and authoritative source for identifying compromised or suspicious endpoints.

  • ✗

    DeviceProcessEvents

    Why it's wrong here

    DeviceProcessEvents captures process creation events, such as executable start time, command-line arguments, and parent-child relationships. Although a process may be responsible for initiating network traffic, this table does not record the destination IPs or network endpoints that were contacted. To tie a process to a specific malicious destination, you must join DeviceProcessEvents with DeviceNetworkEvents.

  • ✗

    DeviceRegistryEvents

    Why it's wrong here

    DeviceRegistryEvents logs changes to the Windows registry, including key creation, value modifications, and persistence mechanisms. Network connections are not stored in the registry and are outside the scope of this table, so querying it would fail to reveal any communications with a threat actor's infrastructure. Registry data might help in later forensic analysis, but it is not how you enumerate communicating devices.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.