Courseiva
Perform threat hunting →hardMultiple Choice

SC-200 Perform threat hunting Practice Question

You are conducting a threat hunt in Microsoft Defender XDR and want to identify devices that have recently communicated with a known C2 server IP address. Which advanced hunting table should you query?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

DeviceNetworkEvents

EviceNetworkEvents (Option A) because this table contains network connection events including destination IP addresses, ports, and protocols. It is used to identify network communications with suspicious IPs such as C2 servers. DeviceProcessEvents (Option D) is for process creation events, DeviceLogonEvents (Option C) is for authentication events, and DeviceFileEvents (Option B) is for file system events. Only DeviceNetworkEvents provides the necessary network traffic information for threat hunting in Microsoft Defender XDR.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    DeviceNetworkEvents

    Why this is correct

    DeviceNetworkEvents is the correct table for C2 hunting because it specifically records network connection attempts, including source and destination IP addresses, ports, protocols, and remote URLs. Unlike file or process events, this table lets you directly search for outbound connections to known malicious or suspicious infrastructure, which is the core signature of command-and-control communications. Without this telemetry, you cannot definitively identify the network egress point to a C2 server.

  • ✗

    DeviceFileEvents

    Why it's wrong here

    DeviceFileEvents is incorrect for this hunt because it only tracks changes to the filesystem, such as when files are created, written, renamed, or deleted. While malware droppers or C2 payloads might leave file-based artifacts, this table contains no destination IP, port, or connection state information. To identify the actual communication with a C2 server, you need network flow data rather than file system activity.

  • ✗

    DeviceLogonEvents

    Why it's wrong here

    DeviceLogonEvents captures authentication and logon sessions, including user accounts, logon types, and success or failure reasons. Even though lateral movement or credential theft may precede C2 usage, the logon event itself never contains the destination IP address of a remote command-and-control channel. Hunting for C2 requires network-connection telemetry, which is outside the scope of logon records.

  • ✗

    DeviceProcessEvents

    Why it's wrong here

    DeviceProcessEvents records process creation and execution details, such as executable paths, command lines, and parent-child relationships. While a process may initiate network calls to a C2 server, the process event table itself does not log the network packets or the destination IP addresses associated with that traffic. You would need to join process activity with DeviceNetworkEvents to see which process connected out, but the destination IPs still come from the network table.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.