Courseiva

SC-200 Respond to security incidents Practice Question

Exhibit

Refer to the exhibit.
```kql
AlertInfo
| where Timestamp > ago(1h)
| join kind=inner AlertEvidence on AlertId
| where EvidenceType == "ip" and EvidenceValue == "203.0.113.1"
| project Timestamp, AlertTitle, EvidenceValue
```

Refer to the exhibit. You run this KQL query in Microsoft 365 Defender advanced hunting to investigate an incident involving IP address 203.0.113.1. The query returns results, but you need to also see which devices communicated with this IP. How should you modify the query?

⚠ Common exam trap

SC-200 often tests whether candidates know which advanced hunting table holds which telemetry type, so the trap is choosing a table that sounds related (like DeviceInfo or IdentityLogonEvents) instead of the one that actually records network connections.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Join with DeviceNetworkEvents on DeviceId where RemoteIP == "203.0.113.1"

The goal is to find which devices communicated with the suspicious IP 203.0.113.1. DeviceNetworkEvents is the advanced hunting table that records network connections from devices, including the RemoteIP field. Joining on DeviceId and filtering where RemoteIP equals the target IP directly surfaces the devices that contacted it.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Join with IdentityLogonEvents on AccountUpn

    Why it's wrong here

    IdentityLogonEvents captures authentication activity keyed by AccountUpn, not device network connections to an IP address, so this join cannot list communicating devices. It is tempting because it correlates identity activity, and would be correct when tracing sign-ins or credential-based attacks for a compromised account.

  • ✓

    Join with DeviceNetworkEvents on DeviceId where RemoteIP == "203.0.113.1"

    Why this is correct

    Joining DeviceNetworkEvents on DeviceId and filtering RemoteIP to 203.0.113.1 correlates the existing results with endpoint network telemetry, satisfying the requirement to identify which devices communicated with that IP. DeviceNetworkEvents records inbound and outbound connections per device, so the join surfaces the missing device context.

  • ✗

    Join with DeviceInfo on DeviceId

    Why it's wrong here

    DeviceInfo holds device inventory attributes, not network connection events, so joining on DeviceId cannot reveal which devices communicated with 203.0.113.1. It is tempting because DeviceInfo is the natural table for device-centric enrichment, and would be correct when you need to add device ownership or OS details to existing device rows.

  • ✗

    Join with EmailEvents on AlertId

    Why it's wrong here

    EmailEvents records mail flow metadata keyed to messages, not device-to-IP network sessions, so joining on AlertId cannot identify communicating devices. It is tempting because AlertId correlates alerts across tables, and EmailEvents would be correct when investigating phishing or email-borne threats tied to a specific alert.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.