Microsoft 365 Certified: Administrator ExpertImplement and manage Microsoft Defender XDRHard

A security analyst is performing an Advanced Hunting query in Microsoft Defender XDR. They need to identify all unique IP addresses that have attempted to connect to a specific internal server (IP: 10.0.0.10) on port 3389 (RDP) over the last 7 days. Which KQL query correctly retrieves this information?

  1. ADeviceNetworkEvents | where RemoteIP == '10.0.0.10' and RemotePort == 3389 | summarize count() by InitiatingProcessFileName
  2. BDeviceNetworkEvents | where LocalIP == '10.0.0.10' and RemotePort == 3389 and Timestamp > ago(7d) | distinct RemoteIP
  3. CDeviceNetworkEvents | where LocalIP == '10.0.0.10' and InitiatingProcessPort == 3389 and Timestamp > ago(7d) | distinct RemoteIP
  4. DDeviceNetworkEvents | where LocalIP == '10.0.0.10' and LocalPort == 3389 and Timestamp > ago(7d) | distinct RemoteIP
Show answer & explanation

Correct answer: D. DeviceNetworkEvents | where LocalIP == '10.0.0.10' and LocalPort == 3389 and Timestamp > ago(7d) | distinct RemoteIP

The correct query identifies network events where the 'LocalIP' is the target server (indicating an incoming connection), the 'LocalPort' is 3389 (RDP), and filters for the last 7 days. `distinct RemoteIP` then extracts the unique source IP addresses. Option B incorrectly uses `InitiatingProcessPort` which is not directly relevant for the *target* port of an incoming connection. Option D incorrectly uses `RemotePort` instead of `LocalPort` for the target server's port. Option A doesn't filter by time and summarizes by process name, not unique IPs.

Why the other options are wrong

  • A. This query incorrectly uses `RemoteIP` for the target server and summarizes by `InitiatingProcessFileName` instead of distinct remote IPs. It also lacks a time filter.
  • B. This query incorrectly uses `RemotePort` instead of `LocalPort`. `RemotePort` would refer to the port on the *connecting* machine, not the target port on the local server.
  • C. This query incorrectly uses `InitiatingProcessPort` which refers to the source port of the initiating process, not the destination port on the local server.

KQL DeviceNetworkEvents Table Fields

The `DeviceNetworkEvents` table in Advanced Hunting records network connections, with `LocalIP` and `LocalPort` representing the destination of incoming connections, and `RemoteIP` and `RemotePort` representing the source.

  • LocalIP: IP address of the device on which the event occurred (destination for incoming).
  • LocalPort: Port on the device on which the event occurred (destination port for incoming).
  • RemoteIP: IP address of the remote device (source for incoming).
  • RemotePort: Port on the remote device (source port for incoming).

Memory trick: Remember, for 'Network' 'Connections', 'Local' is 'Destination', 'Remote' is 'Source', and 'distinct' finds 'Unique'.

More Implement and manage Microsoft Defender XDR questions