easyMultiple Choice
SC-200 Practice Question: A security analyst is investigating a malware…
A security analyst is investigating a malware outbreak and needs to find all devices where a specific malicious file with a known SHA1 hash has been observed in the last 24 hours. Which Advanced Hunting table in Microsoft 365 Defender should be the primary source for this query?
⚠ Common exam trap
It's easy for candidates to confuse file observation with process execution or network activity, leading them to choose DeviceProcessEvents or DeviceNetworkEvents, but DeviceFileEvents is the only table that directly records the presence of a file by its hash on a device.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DeviceFileEvents
DeviceFileEvents is the correct table because it specifically records file creation, modification, and deletion events on endpoints, including the SHA1 hash of files. To find all devices where a specific malicious file with a known SHA1 hash has been observed, this table provides the direct file-level telemetry needed for the query.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
DeviceFileEvents
Why this is correct
DeviceFileEvents is the correct table because it records every file creation, modification, rename, and deletion event on endpoints via Microsoft Defender for Endpoint, including the file's SHA1/SHA256 hashes, full path, device ID, and timestamp. This makes it ideal for a query that screens all devices for a specific malware hash, since the file must exist on disk before it can be executed or otherwise cause network activity. The table is filesystem-centric, so it directly identifies affected machines regardless of whether the file has been run.
- ✗
EmailAttachmentInfo
Why it's wrong here
EmailAttachmentInfo stores metadata about email attachments processed by Microsoft 365 Defender, such as sender, recipient, subject, attachment name, and attachment hash. While this can reveal that a malicious file was delivered via email, it does not record whether the attachment was saved, written, or otherwise present on any endpoint's local filesystem. Therefore, it cannot tell you which devices currently contain a file matching the hash, only which mailboxes or recipients received it.
- ✗
DeviceProcessEvents
Why it's wrong here
DeviceProcessEvents logs process creation events, including the process image's path, command line, and the SHA1/SHA256 hash of the executable that was launched. It can find devices that ran a file with the malware hash, but it misses files that are written to disk but never executed, such as a dropper writing a payload DLL, a macro-saved script, or a staged artifact. Because the question asks for devices with a specific file hash—regardless of execution—a process-creation table provides an incomplete and potentially false-negative result.
- ✗
DeviceNetworkEvents
Why it's wrong here
DeviceNetworkEvents records network connection activity for endpoints, including local and remote IP addresses, ports, protocols, and connection direction, but it does not contain any file hash or filesystem path fields. A device with a malicious file on disk may never establish a network connection, and network telemetry is therefore orthogonal to file presence on the endpoint. This table is useful for infection-spread analysis, but it cannot directly answer which devices have a given file hash.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.