SC-200 Perform threat hunting • 25 Questions
25 SC-200 Perform threat hunting practice questions with answers and explanations. Free, no signup.
A threat hunter is using Microsoft Defender for Endpoint advanced hunting to investigate a suspicious process that was observed launching from a temporary folder. The hunter wants to find all devices that have executed this specific process (with the same SHA256 hash) in the last 24 hours. Which table and column should be used in the query?
Choose an answer to begin — your selection is scored in the full session.
25 questions · instant feedback and full explanations after every question.