Courseiva

SC-100 Practice Question: Design security operations, identity, and compliance capabilities

Exhibit

Refer to the exhibit.

{
    "alertRuleTemplate": "Suspicious process execution",
    "displayName": "Custom Rule - Suspicious PowerShell",
    "description": "Detects suspicious PowerShell commands",
    "query": "DeviceProcessEvents | where FileName in~ ('powershell.exe', 'pwsh.exe') | where ProcessCommandLine has_any ('-EncodedCommand', '-e ', 'Invoke-Expression')",
    "severity": "High",
    "queryFrequency": "PT1H",
    "queryPeriod": "PT1H",
    "triggerOperator": "GreaterThan",
    "triggerThreshold": 5
}

You are analyzing a custom detection rule in Microsoft 365 Defender. Based on the exhibit, what is a potential operational issue with this rule?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The threshold is too low, leading to alert fatigue.

Option A is correct because a custom detection rule whose threshold is set too low will trigger on very few or even a single event, generating excessive alerts that overwhelm analysts with false positives and cause alert fatigue. In Microsoft 365 Defender custom detections, the threshold (aggregation) value controls how many events must occur within the query's timeframe before an alert fires, so setting it too low directly increases alert volume. Option B is incorrect because the scenario asks about an operational issue, not a syntax error, and the exhibit implies the query runs. Option C is incorrect because severity is a triage preference, not an operational defect, and changing High to Medium would not fix alert volume. Option D is incorrect because PowerShell 7 coverage depends on the query's data source and process filters, not on the threshold, and the scenario does not indicate pwsh.exe is relevant.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The threshold is too low, leading to alert fatigue.

    Why this is correct

    A threshold of 5 events in a day, combined with a High severity rating and a rule that matches common PowerShell processes, will produce a large number of alerts from benign administrative and scripting activity. This overwhelms the SOC with low-fidelity alerts, desensitizing analysts to genuinely malicious signals and increasing the risk that a true positive is buried in the noise. The fundamental problem is the low threshold causing alert fatigue, not a technical defect in the query.

  • ✗

    The query syntax is invalid.

    Why it's wrong here

    The custom detection rule's KQL query uses standard verbs like `let`, `where`, and `or` with proper column references from the DeviceProcessEvents schema, and would pass Microsoft 365 Defender's validation when saved. A syntactically invalid query would be rejected at creation time with a parser error, preventing the rule from ever being enabled. Since the rule is active and generating alerts, the syntax is demonstrably correct.

  • ✗

    The severity should be Medium instead of High.

    Why it's wrong here

    Changing the severity from High to Medium would alter how the alert ranks in the queue and its escalation path, but it would not reduce the number of alerts generated because severity is a label applied to each alert, not a trigger condition. The rule still fires at the same 5-event threshold, so the SOC would face the same overwhelming alert volume regardless of the assigned severity. Therefore this criticism fails to address the actual root cause of the alert fatigue.

  • ✗

    The rule does not cover PowerShell 7 (pwsh.exe).

    Why it's wrong here

    The query explicitly includes both `powershell.exe` and `pwsh.exe` in the file-name filter, meaning the rule covers Windows PowerShell 5.1 and PowerShell 7 instances equally. A true coverage gap for PowerShell 7 would be a legitimate finding, but it is not applicable here because the rule's process filter already accounts for both executables. As a result, this option is a factually incorrect objection.

About these practice questions

Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.