SC-200 Practice Question 3842

Exam: SC-200
Domain: Perform threat hunting
Difficulty: medium
In Microsoft Defender XDR, which table tracks user logon events across domain-joined Windows machines, including local console logins and network NTLM/Kerberos logons?

Answer Options

A
The DeviceLogonEvents table
B
The DeviceFileCertificateInfo table
C
The DeviceRegistryEvents table
D
The AppFileEvents table

Correct Answer

A: The DeviceLogonEvents table

Explanation

The DeviceLogonEvents table records local and network logon sessions, logon types (e.g., Interactive, RemoteInteractive, Network), and account credentials used on the device.