SC-200 Perform threat hunting Practice Question
You are a threat hunter using Microsoft Defender XDR. You want to identify all devices that have communicated with a known malicious IP address 203.0.113.10 in the last 30 days. Which Advanced Hunting query should you run?
⚠ Common exam trap
The trap here is selecting tables based on the presence of an IP field without verifying that the table actually records network communications; only DeviceNetworkEvents captures general network connections.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DeviceNetworkEvents | where RemoteIP == "203.0.113.10" and Timestamp > ago(30d)
DeviceNetworkEvents is the correct Advanced Hunting table for network connection data. It includes fields such as RemoteIP, RemotePort, and LocalIP. By filtering for the specific malicious IP address and limiting to the last 30 days using Timestamp > ago(30d), you can retrieve all devices that communicated with that IP. This query provides the necessary visibility for threat hunting network-based indicators.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
DeviceFileEvents | where RemoteIP == "203.0.113.10" and Timestamp > ago(30d)
Why it's wrong here
DeviceFileEvents tracks file system activities, such as file creation, modification, and deletion. It does not contain network-related fields like RemoteIP. This table is used for hunting file-based indicators, not network communications. Running this query would not yield any devices that communicated with the IP address, and it misunderstands the schema for network events in Microsoft Defender XDR.
- ✗
DeviceEvents | where RemoteIP == "203.0.113.10" and Timestamp > ago(30d)
Why it's wrong here
DeviceEvents contains various event types, such as process creation, registry modifications, and file events, but it does not include network connection details like RemoteIP. The RemoteIP field is not present in DeviceEvents; network events are stored in DeviceNetworkEvents. Therefore, this query would return no results or an error, and it fails to identify devices communicating with the malicious IP.
- ✗
DeviceLogonEvents | where RemoteIP == "203.0.113.10" and Timestamp > ago(30d)
Why it's wrong here
DeviceLogonEvents contains logon and authentication events, not network connections. While it may have a RemoteIP field for logon source IPs, it only captures logon attempts, not general network communications. A device could communicate with the malicious IP without logging on. Therefore, this query would miss many communication instances and is not the appropriate table for identifying all devices that communicated with the IP.
- ✓
DeviceNetworkEvents | where RemoteIP == "203.0.113.10" and Timestamp > ago(30d)
Why this is correct
DeviceNetworkEvents contains network connection events from devices, including the remote IP address. Filtering by RemoteIP equal to the malicious IP and a timestamp within the last 30 days will return all devices that communicated with that IP. This is the correct table and fields for this purpose. The Timestamp field is used for time filtering in Advanced Hunting, and the query is straightforward and effective.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.