Courseiva
Perform threat hunting →easyMultiple Choice

SC-200 Perform threat hunting Practice Question

During a threat hunt, you want to identify processes that have made network connections to known malicious IP addresses. Which data source in Microsoft Defender for Endpoint would provide the necessary information?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

DeviceNetworkEvents

DeviceNetworkEvents logs network connections including destination IP addresses, which is needed for this threat hunt. Option A is wrong because DeviceFileEvents logs file operations, not network connections. Option C is wrong because DeviceProcessEvents logs process creation, not network connections. Option D is wrong because DeviceRegistryEvents logs registry changes, not network connections.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    DeviceFileEvents

    Why it's wrong here

    DeviceFileEvents captures file creation, modification and deletion activity, so it contains no remote IP or connection metadata to correlate with malicious addresses. It is the correct source when hunting dropped payloads, ransomware file encryption or persistence artefacts written to disk.

  • ✓

    DeviceNetworkEvents

    Why this is correct

    DeviceNetworkEvents records outbound and inbound connection attempts per device, including remote IP addresses, ports and the initiating process. Correlating these events against threat intelligence identifies processes connecting to known malicious IPs, satisfying the hunt requirement.

  • ✗

    DeviceProcessEvents

    Why it's wrong here

    DeviceProcessEvents records process creation, command lines and parent-child relationships, not network endpoints; it holds no remote IP field to match against threat intelligence. It is the right table for hunting suspicious process executions or encoded PowerShell, where the process itself, rather than its connection, is the indicator.

  • ✗

    DeviceRegistryEvents

    Why it's wrong here

    DeviceRegistryEvents records registry key creation, modification and deletion on endpoints, containing no network connection data. It is tempting because registry changes often indicate persistence, but identifying connections to malicious IP addresses requires DeviceNetworkEvents, which logs remote IPs and ports.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.