Courseiva
Perform threat hunting →easyMultiple Choice

SC-200 Perform threat hunting Practice Question

You are a threat hunter in Microsoft Sentinel. You want to identify all devices that have communicated with a known malicious IP address (e.g., 203.0.113.5) over the past week. Which data source should you query to find network connection events?

⚠ Common exam trap

The trap here is assuming that any network log source, such as CommonSecurityLog or AzureNetworkAnalytics_CL, will provide complete endpoint connection data, when only DeviceNetworkEvents offers the necessary endpoint-centric network telemetry.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

DeviceNetworkEvents

DeviceNetworkEvents is the correct data source because it captures endpoint network connections, including remote IP addresses, and is available in Microsoft Sentinel through the Microsoft Defender XDR connector. Querying it for the malicious IP will reveal all devices that communicated with it. Other sources like CommonSecurityLog or Syslog may have some network data but are not as comprehensive or endpoint-focused.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    DeviceNetworkEvents

    Why this is correct

    DeviceNetworkEvents in Microsoft Defender XDR (ingested into Microsoft Sentinel via the Defender XDR connector) provides detailed network connection events from endpoints, including remote IP addresses. Querying this table for the malicious IP will identify all devices that connected to it, directly fulfilling the hunting requirement.

  • ✗

    AzureNetworkAnalytics_CL

    Why it's wrong here

    AzureNetworkAnalytics_CL contains network flow logs from Azure Network Watcher, which cover Azure virtual network traffic but not endpoint communications. It would not capture connections from on-premises devices or endpoints outside Azure. The scenario requires all devices, so this table is too limited in scope.

  • ✗

    CommonSecurityLog

    Why it's wrong here

    CommonSecurityLog contains security events from various appliances, such as firewalls and proxies, and may include network connections. However, it is not the primary source for endpoint network telemetry in Microsoft Sentinel. The scenario seeks all devices communicating with a malicious IP, which is best served by endpoint network connection logs, not generic security logs that may not cover all devices.

  • ✗

    Syslog

    Why it's wrong here

    Syslog contains log messages from Linux and network devices, which may include firewall or router logs. However, it is not a standardized source for endpoint network connection events and often lacks the granularity to identify specific remote IP connections from all devices. It is not the best choice for this hunt.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.