SC-200 Perform threat hunting Practice Question
During a threat hunt, you want to identify processes that have made network connections to known malicious IP addresses. Which data source in Microsoft Defender for Endpoint would provide the necessary information?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DeviceNetworkEvents
DeviceNetworkEvents logs network connections including destination IP addresses, which is needed for this threat hunt. Option A is wrong because DeviceFileEvents logs file operations, not network connections. Option C is wrong because DeviceProcessEvents logs process creation, not network connections. Option D is wrong because DeviceRegistryEvents logs registry changes, not network connections.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
DeviceFileEvents
Why it's wrong here
DeviceFileEvents captures file creation, modification and deletion activity, so it contains no remote IP or connection metadata to correlate with malicious addresses. It is the correct source when hunting dropped payloads, ransomware file encryption or persistence artefacts written to disk.
- ✓
DeviceNetworkEvents
Why this is correct
DeviceNetworkEvents records outbound and inbound connection attempts per device, including remote IP addresses, ports and the initiating process. Correlating these events against threat intelligence identifies processes connecting to known malicious IPs, satisfying the hunt requirement.
- ✗
DeviceProcessEvents
Why it's wrong here
DeviceProcessEvents records process creation, command lines and parent-child relationships, not network endpoints; it holds no remote IP field to match against threat intelligence. It is the right table for hunting suspicious process executions or encoded PowerShell, where the process itself, rather than its connection, is the indicator.
- ✗
DeviceRegistryEvents
Why it's wrong here
DeviceRegistryEvents records registry key creation, modification and deletion on endpoints, containing no network connection data. It is tempting because registry changes often indicate persistence, but identifying connections to malicious IP addresses requires DeviceNetworkEvents, which logs remote IPs and ports.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.