Courseiva
Perform threat hunting →easyMultiple Choice

SC-200 Perform threat hunting Practice Question

You are hunting for signs of credential theft in Microsoft Defender XDR. Which advanced hunting table is most appropriate to investigate suspicious logon events?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

IdentityLogonEvents

IdentityLogonEvents contains authentication logs, which are most relevant for investigating suspicious logon events and credential theft. Option A (DeviceNetworkEvents) is for network connections. Option B (DeviceProcessEvents) is for process events. Option C (EmailEvents) is for email records.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    DeviceNetworkEvents

    Why it's wrong here

    DeviceNetworkEvents records network connections and listening ports on endpoints, not authentication activity, so it cannot surface suspicious logons. It is tempting because credential theft often involves outbound command-and-control traffic, and this table would be the right choice when hunting for malicious network connections rather than logon anomalies.

  • ✗

    DeviceProcessEvents

    Why it's wrong here

    DeviceProcessEvents captures process creation and command lines, useful for detecting credential-dumping tool execution. Suspicious logon activity itself, however, appears in DeviceLogonEvents, so this table shows the tooling rather than the authentication events the hunt targets.

  • ✗

    EmailEvents

    Why it's wrong here

    EmailEvents records message delivery, sender and attachment metadata, not authentication activity. It is the right table for investigating phishing or malicious mail, but credential theft requires logon telemetry such as DeviceLogonEvents, which EmailEvents does not contain.

  • ✓

    IdentityLogonEvents

    Why this is correct

    IdentityLogonEvents records authentication activity across Microsoft Entra ID and on-premises identity infrastructure, including logon type, application and failure reasons. This makes it the appropriate table for surfacing anomalous or suspicious logon patterns indicative of credential theft.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.