SC-200 Practice Question 3842
Exam: SC-200
Domain: Perform threat hunting
Difficulty: medium
In Microsoft Defender XDR, which table tracks user logon events across domain-joined Windows machines, including local console logins and network NTLM/Kerberos logons?
Answer Options
A
The DeviceLogonEvents table
B
The DeviceFileCertificateInfo table
C
The DeviceRegistryEvents table
D
The AppFileEvents table
Correct Answer
A: The DeviceLogonEvents table
Explanation
The DeviceLogonEvents table records local and network logon sessions, logon types (e.g., Interactive, RemoteInteractive, Network), and account credentials used on the device.