SC-200 Perform threat hunting Practice Question
You are performing a threat hunt in Microsoft Sentinel. You want to identify devices that have been communicating with known malicious IP addresses. Which data source should you query?
⚠ Common exam trap
Candidates often choose DnsEvents thinking DNS logs show all network communications, but they miss that DNS only resolves domain names to IPs and does not log the actual IP connections, which are captured in CommonSecurityLog from firewalls or proxies.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
CommonSecurityLog
CommonSecurityLog is the correct data source because it aggregates logs from various security appliances (e.g., firewalls, proxies) using the Syslog or CEF format. These logs typically contain source and destination IP addresses, making them ideal for correlating internal devices with known malicious IPs during a threat hunt. SecurityEvent and DeviceNetworkEvents lack the necessary network-level IP communication data, while DnsEvents only logs DNS queries, not direct IP connections.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
SecurityEvent
Why it's wrong here
SecurityEvent captures Windows operating system audit logs, such as successful or failed logon events (4624/4625) and process creation (4688). It is focused on local security and user activity on hosts, not on the flow of packets or IP sessions across your network. Since it includes no source/destination IP pairs for inter-host communication, it will not help you trace direct connections between systems.
- ✓
CommonSecurityLog
Why this is correct
CommonSecurityLog is the Sentinel table that ingests normalized network traffic logs from firewalls and other security appliances using the Common Event Format (CEF). It records fields like source and destination IP addresses, ports, protocols, and the action taken (allow/deny), making it the go-to table for analyzing inter-host IP communication. For a hunt focused on direct network connections between two systems, this is the appropriate data source.
- ✗
DnsEvents
Why it's wrong here
DnsEvents holds DNS query and response activity, such as which client resolver asked for a specific domain name and what IP address the server returned. It reveals name-resolution behavior, not the actual connection path or direct IP-to-IP traffic between endpoints. If you are hunting for hosts communicating directly, DNS logs can only show the resolution step, not the subsequent connection, so it would miss the target evidence.
- ✗
DeviceNetworkEvents
Why it's wrong here
DeviceNetworkEvents is generated by Microsoft Defender for Endpoint sensors on individual devices and records outbound and inbound connections initiated by specific processes. While it does include IP addresses and ports, it is endpoint-centric telemetry, not a central firewall log, and it only covers devices with the Defender agent installed. For authoritative firewall traffic from network appliances, CommonSecurityLog is the expected source.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.