Courseiva
easyMultiple Choice

SC-200 Practice Question: A security analyst is investigating a malware…

A security analyst is investigating a malware outbreak and needs to find all devices where a specific malicious file with a known SHA1 hash has been observed in the last 24 hours. Which Advanced Hunting table in Microsoft 365 Defender should be the primary source for this query?

⚠ Common exam trap

It's easy for candidates to confuse file observation with process execution or network activity, leading them to choose DeviceProcessEvents or DeviceNetworkEvents, but DeviceFileEvents is the only table that directly records the presence of a file by its hash on a device.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

DeviceFileEvents

DeviceFileEvents is the correct table because it specifically records file creation, modification, and deletion events on endpoints, including the SHA1 hash of files. To find all devices where a specific malicious file with a known SHA1 hash has been observed, this table provides the direct file-level telemetry needed for the query.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    DeviceFileEvents

    Why this is correct

    DeviceFileEvents is the correct table because it records every file creation, modification, rename, and deletion event on endpoints via Microsoft Defender for Endpoint, including the file's SHA1/SHA256 hashes, full path, device ID, and timestamp. This makes it ideal for a query that screens all devices for a specific malware hash, since the file must exist on disk before it can be executed or otherwise cause network activity. The table is filesystem-centric, so it directly identifies affected machines regardless of whether the file has been run.

  • ✗

    EmailAttachmentInfo

    Why it's wrong here

    EmailAttachmentInfo stores metadata about email attachments processed by Microsoft 365 Defender, such as sender, recipient, subject, attachment name, and attachment hash. While this can reveal that a malicious file was delivered via email, it does not record whether the attachment was saved, written, or otherwise present on any endpoint's local filesystem. Therefore, it cannot tell you which devices currently contain a file matching the hash, only which mailboxes or recipients received it.

  • ✗

    DeviceProcessEvents

    Why it's wrong here

    DeviceProcessEvents logs process creation events, including the process image's path, command line, and the SHA1/SHA256 hash of the executable that was launched. It can find devices that ran a file with the malware hash, but it misses files that are written to disk but never executed, such as a dropper writing a payload DLL, a macro-saved script, or a staged artifact. Because the question asks for devices with a specific file hash—regardless of execution—a process-creation table provides an incomplete and potentially false-negative result.

  • ✗

    DeviceNetworkEvents

    Why it's wrong here

    DeviceNetworkEvents records network connection activity for endpoints, including local and remote IP addresses, ports, protocols, and connection direction, but it does not contain any file hash or filesystem path fields. A device with a malicious file on disk may never establish a network connection, and network telemetry is therefore orthogonal to file presence on the endpoint. This table is useful for infection-spread analysis, but it cannot directly answer which devices have a given file hash.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.