SC-200 Respond to security incidents Practice Question
Exhibit
Refer to the exhibit. ```kql AlertInfo | where Timestamp > ago(1h) | join kind=inner AlertEvidence on AlertId | where EvidenceType == "ip" and EvidenceValue == "203.0.113.1" | project Timestamp, AlertTitle, EvidenceValue ```
Refer to the exhibit. You run this KQL query in Microsoft 365 Defender advanced hunting to investigate an incident involving IP address 203.0.113.1. The query returns results, but you need to also see which devices communicated with this IP. How should you modify the query?
⚠ Common exam trap
SC-200 often tests whether candidates know which advanced hunting table holds which telemetry type, so the trap is choosing a table that sounds related (like DeviceInfo or IdentityLogonEvents) instead of the one that actually records network connections.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Join with DeviceNetworkEvents on DeviceId where RemoteIP == "203.0.113.1"
The goal is to find which devices communicated with the suspicious IP 203.0.113.1. DeviceNetworkEvents is the advanced hunting table that records network connections from devices, including the RemoteIP field. Joining on DeviceId and filtering where RemoteIP equals the target IP directly surfaces the devices that contacted it.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Join with IdentityLogonEvents on AccountUpn
Why it's wrong here
IdentityLogonEvents captures authentication activity keyed by AccountUpn, not device network connections to an IP address, so this join cannot list communicating devices. It is tempting because it correlates identity activity, and would be correct when tracing sign-ins or credential-based attacks for a compromised account.
- ✓
Join with DeviceNetworkEvents on DeviceId where RemoteIP == "203.0.113.1"
Why this is correct
Joining DeviceNetworkEvents on DeviceId and filtering RemoteIP to 203.0.113.1 correlates the existing results with endpoint network telemetry, satisfying the requirement to identify which devices communicated with that IP. DeviceNetworkEvents records inbound and outbound connections per device, so the join surfaces the missing device context.
- ✗
Join with DeviceInfo on DeviceId
Why it's wrong here
DeviceInfo holds device inventory attributes, not network connection events, so joining on DeviceId cannot reveal which devices communicated with 203.0.113.1. It is tempting because DeviceInfo is the natural table for device-centric enrichment, and would be correct when you need to add device ownership or OS details to existing device rows.
- ✗
Join with EmailEvents on AlertId
Why it's wrong here
EmailEvents records mail flow metadata keyed to messages, not device-to-IP network sessions, so joining on AlertId cannot identify communicating devices. It is tempting because AlertId correlates alerts across tables, and EmailEvents would be correct when investigating phishing or email-borne threats tied to a specific alert.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.