SC-200 Perform threat hunting Practice Question
You are hunting for signs of credential theft in Microsoft Defender XDR. Which advanced hunting table is most appropriate to investigate suspicious logon events?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
IdentityLogonEvents
IdentityLogonEvents contains authentication logs, which are most relevant for investigating suspicious logon events and credential theft. Option A (DeviceNetworkEvents) is for network connections. Option B (DeviceProcessEvents) is for process events. Option C (EmailEvents) is for email records.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
DeviceNetworkEvents
Why it's wrong here
DeviceNetworkEvents records network connections and listening ports on endpoints, not authentication activity, so it cannot surface suspicious logons. It is tempting because credential theft often involves outbound command-and-control traffic, and this table would be the right choice when hunting for malicious network connections rather than logon anomalies.
- ✗
DeviceProcessEvents
Why it's wrong here
DeviceProcessEvents captures process creation and command lines, useful for detecting credential-dumping tool execution. Suspicious logon activity itself, however, appears in DeviceLogonEvents, so this table shows the tooling rather than the authentication events the hunt targets.
- ✗
EmailEvents
Why it's wrong here
EmailEvents records message delivery, sender and attachment metadata, not authentication activity. It is the right table for investigating phishing or malicious mail, but credential theft requires logon telemetry such as DeviceLogonEvents, which EmailEvents does not contain.
- ✓
IdentityLogonEvents
Why this is correct
IdentityLogonEvents records authentication activity across Microsoft Entra ID and on-premises identity infrastructure, including logon type, application and failure reasons. This makes it the appropriate table for surfacing anomalous or suspicious logon patterns indicative of credential theft.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.