During a threat hunt, an analyst discovers that a user's device has been sending large amounts of data to an external IP address associated with a known C2 server. The analyst wants to trace the process responsible for the outbound connections. Which Microsoft Defender for Endpoint advanced hunting table should be queried to find the process that initiated the network connections?
DeviceNetworkEvents is the Advanced Hunting table designed to capture network connection attempts, including local/remote IPs, ports, protocol, and connection state. Critically, it includes the initiating process information (InitiatingProcessId, InitiatingProcessFileName, InitiatingProcessCommandLine), so you can directly attribute the outbound connection to the user's dev process. This makes it the correct choice when the analyst needs the process responsible for an outbound connection.
Why this answer
DeviceNetworkEvents in Microsoft Defender for Endpoint advanced hunting contains network connection events, including the initiating process, remote IP, port, and protocol. To trace which process initiated outbound connections to a known C2 IP, the analyst must query DeviceNetworkEvents, which correlates network activity with the responsible process. This table is purpose-built for network connection telemetry.
Exam trap
SC-200 often tests the distinction between process, file, network, and generic event tables, so candidates must know exactly which table holds network connection telemetry with process attribution.
How to eliminate wrong answers
Option A is wrong because DeviceProcessEvents records process creation, termination, and command-line details, but not network connections, so it cannot directly show which process sent data to an external IP. Option B is wrong because DeviceFileEvents captures file creation, modification, and deletion activity, not network traffic. Option D is wrong because DeviceEvents is a general-purpose table for miscellaneous events like registry changes, logon events, and script execution, not specifically network connection initiations.