Courseiva
mediumMultiple Choice

SC-200 Practice Question: A security analyst is investigating a potential…

A security analyst is investigating a potential malware outbreak detected by Microsoft 365 Defender. The analyst needs to identify all devices that have executed a specific parent process with a given ProcessId. Which column in the DeviceProcessEvents table should be used to find processes whose parent is the specified process?

⚠ Common exam trap

A common mix-up: candidates confuse InitiatingProcessId (which often appears in alert schemas for the root process of an incident) with ParentProcessId, not realizing that in DeviceProcessEvents, the direct parent-child relationship is stored in ParentProcessId, not InitiatingProcessId.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

ParentProcessId

The ParentProcessId column in the DeviceProcessEvents table stores the process ID (PID) of the parent process that initiated the current process. To find all child processes spawned by a specific parent process with a known ProcessId, you query the ParentProcessId column for that value. This directly links child processes to their parent, enabling the analyst to trace the malware's execution chain.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    ParentProcessId

    Why this is correct

    ParentProcessId is the process identifier of the process that created the current process; it directly represents the immediate parent in the process tree. By filtering on this field, an analyst can quickly isolate all child processes spawned by a suspected malware process, enabling lineage-based detection. This is the correct field for defining direct process ancestry, unlike ProcessId or LogonId.

  • ✗

    InitiatingProcessId

    Why it's wrong here

    InitiatingProcessId, as defined in many telemetry schemas, points to the original root process that started an entire activity chain, not necessarily the direct creator of a given process. For example, if an Office document launches PowerShell, which then runs cmd.exe, InitiatingProcessId on cmd.exe may reference the Office process rather than PowerShell. Relying on it to filter immediate children would skip intermediate processes and could overinclude processes in the same chain, making it inappropriate for direct parent-child analysis.

  • ✗

    ProcessId

    Why it's wrong here

    ProcessId identifies the current process itself, the subject under investigation, rather than its origin. Querying by ProcessId returns the process's own row and says nothing about which process created it or which processes it has spawned. Therefore it cannot be used to reconstruct parent-child relationships; you would need a separate field such as ParentProcessId to move up the process tree.

  • ✗

    LogonId

    Why it's wrong here

    LogonId is a numerical identifier for a Windows logon session, representing a security context under which processes run, not an individual process. A single logon session typically hosts many processes and services, so it provides no information about process ancestry or which process spawned another. Using LogonId would group together all processes in a session, but it would not differentiate between a process and its children.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.