Courseiva
Perform threat hunting →hardMultiple Choice

SC-200 DeviceNetworkEvents Practice Question

During a threat hunt, an analyst discovers that a user's device has been sending large amounts of data to an external IP address associated with a known C2 server. The analyst wants to trace the process responsible for the outbound connections. Which Microsoft Defender for Endpoint advanced hunting table should be queried to find the process that initiated the network connections?

⚠ Common exam trap

SC-200 often tests the distinction between process, file, network, and generic event tables, so candidates must know exactly which table holds network connection telemetry with process attribution.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

DeviceNetworkEvents

DeviceNetworkEvents in Microsoft Defender for Endpoint advanced hunting contains network connection events, including the initiating process, remote IP, port, and protocol. To trace which process initiated outbound connections to a known C2 IP, the analyst must query DeviceNetworkEvents, which correlates network activity with the responsible process. This table is purpose-built for network connection telemetry.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    DeviceProcessEvents

    Why it's wrong here

    DeviceProcessEvents records process creation events (image name, command line, parent process) but does not contain network connection data such as remote IP/port or the relationship between an established outbound connection and the process that initiated it. To identify the process responsible for an outbound connection, you need a network-connection event table with InitiatingProcess fields, not process-creation logs. Therefore this table cannot answer the analyst's need.

  • ✗

    DeviceFileEvents

    Why it's wrong here

    DeviceFileEvents logs file system operations including file creation, modification, renaming, and deletion, plus SHA1/SHA256 hashes. It has no schema for source/destination IPs, ports, or connection states, and it lacks the InitiatingProcessId/InitiatingProcessFileName fields that tie a specific outbound connection back to a process. File events might reveal droppers or scripts, but they do not capture the live network connection itself, making them incorrect for this query.

  • ✓

    DeviceNetworkEvents

    Why this is correct

    DeviceNetworkEvents is the Advanced Hunting table designed to capture network connection attempts, including local/remote IPs, ports, protocol, and connection state. Critically, it includes the initiating process information (InitiatingProcessId, InitiatingProcessFileName, InitiatingProcessCommandLine), so you can directly attribute the outbound connection to the user's dev process. This makes it the correct choice when the analyst needs the process responsible for an outbound connection.

  • ✗

    DeviceEvents

    Why it's wrong here

    DeviceEvents is a generic table for custom events and various system-level events that don't fit into specialized schema; it does not expose structured network connection data or the initiating-process attributes required for outbound connection attribution. While a custom event might contain network context if explicitly logged, the standard DeviceEvents schema lacks fields like RemoteIP, RemotePort, and InitiatingProcessId. Microsoft 365 Defender uses DeviceNetworkEvents as the dedicated network connection table, so DeviceEvents would be an unreliable and incorrect source here.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.