SC-200 DeviceNetworkEvents Practice Question
During a threat hunt, an analyst discovers that a user's device has been sending large amounts of data to an external IP address associated with a known C2 server. The analyst wants to trace the process responsible for the outbound connections. Which Microsoft Defender for Endpoint advanced hunting table should be queried to find the process that initiated the network connections?
⚠ Common exam trap
SC-200 often tests the distinction between process, file, network, and generic event tables, so candidates must know exactly which table holds network connection telemetry with process attribution.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DeviceNetworkEvents
DeviceNetworkEvents in Microsoft Defender for Endpoint advanced hunting contains network connection events, including the initiating process, remote IP, port, and protocol. To trace which process initiated outbound connections to a known C2 IP, the analyst must query DeviceNetworkEvents, which correlates network activity with the responsible process. This table is purpose-built for network connection telemetry.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
DeviceProcessEvents
Why it's wrong here
DeviceProcessEvents records process creation events (image name, command line, parent process) but does not contain network connection data such as remote IP/port or the relationship between an established outbound connection and the process that initiated it. To identify the process responsible for an outbound connection, you need a network-connection event table with InitiatingProcess fields, not process-creation logs. Therefore this table cannot answer the analyst's need.
- ✗
DeviceFileEvents
Why it's wrong here
DeviceFileEvents logs file system operations including file creation, modification, renaming, and deletion, plus SHA1/SHA256 hashes. It has no schema for source/destination IPs, ports, or connection states, and it lacks the InitiatingProcessId/InitiatingProcessFileName fields that tie a specific outbound connection back to a process. File events might reveal droppers or scripts, but they do not capture the live network connection itself, making them incorrect for this query.
- ✓
DeviceNetworkEvents
Why this is correct
DeviceNetworkEvents is the Advanced Hunting table designed to capture network connection attempts, including local/remote IPs, ports, protocol, and connection state. Critically, it includes the initiating process information (InitiatingProcessId, InitiatingProcessFileName, InitiatingProcessCommandLine), so you can directly attribute the outbound connection to the user's dev process. This makes it the correct choice when the analyst needs the process responsible for an outbound connection.
- ✗
DeviceEvents
Why it's wrong here
DeviceEvents is a generic table for custom events and various system-level events that don't fit into specialized schema; it does not expose structured network connection data or the initiating-process attributes required for outbound connection attribution. While a custom event might contain network context if explicitly logged, the standard DeviceEvents schema lacks fields like RemoteIP, RemotePort, and InitiatingProcessId. Microsoft 365 Defender uses DeviceNetworkEvents as the dedicated network connection table, so DeviceEvents would be an unreliable and incorrect source here.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.