SC-200 Perform threat hunting Practice Question
You are a threat hunter in Microsoft Sentinel. You want to identify all devices that have communicated with a known malicious IP address (e.g., 203.0.113.5) over the past week. Which data source should you query to find network connection events?
⚠ Common exam trap
The trap here is assuming that any network log source, such as CommonSecurityLog or AzureNetworkAnalytics_CL, will provide complete endpoint connection data, when only DeviceNetworkEvents offers the necessary endpoint-centric network telemetry.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DeviceNetworkEvents
DeviceNetworkEvents is the correct data source because it captures endpoint network connections, including remote IP addresses, and is available in Microsoft Sentinel through the Microsoft Defender XDR connector. Querying it for the malicious IP will reveal all devices that communicated with it. Other sources like CommonSecurityLog or Syslog may have some network data but are not as comprehensive or endpoint-focused.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
DeviceNetworkEvents
Why this is correct
DeviceNetworkEvents in Microsoft Defender XDR (ingested into Microsoft Sentinel via the Defender XDR connector) provides detailed network connection events from endpoints, including remote IP addresses. Querying this table for the malicious IP will identify all devices that connected to it, directly fulfilling the hunting requirement.
- ✗
AzureNetworkAnalytics_CL
Why it's wrong here
AzureNetworkAnalytics_CL contains network flow logs from Azure Network Watcher, which cover Azure virtual network traffic but not endpoint communications. It would not capture connections from on-premises devices or endpoints outside Azure. The scenario requires all devices, so this table is too limited in scope.
- ✗
CommonSecurityLog
Why it's wrong here
CommonSecurityLog contains security events from various appliances, such as firewalls and proxies, and may include network connections. However, it is not the primary source for endpoint network telemetry in Microsoft Sentinel. The scenario seeks all devices communicating with a malicious IP, which is best served by endpoint network connection logs, not generic security logs that may not cover all devices.
- ✗
Syslog
Why it's wrong here
Syslog contains log messages from Linux and network devices, which may include firewall or router logs. However, it is not a standardized source for endpoint network connection events and often lacks the granularity to identify specific remote IP connections from all devices. It is not the best choice for this hunt.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.