mediumMultiple Choice
SC-200 Practice Question: A security analyst is investigating a potential…
A security analyst is investigating a potential malware outbreak detected by Microsoft 365 Defender. The analyst needs to identify all devices that have executed a specific parent process with a given ProcessId. Which column in the DeviceProcessEvents table should be used to find processes whose parent is the specified process?
⚠ Common exam trap
A common mix-up: candidates confuse InitiatingProcessId (which often appears in alert schemas for the root process of an incident) with ParentProcessId, not realizing that in DeviceProcessEvents, the direct parent-child relationship is stored in ParentProcessId, not InitiatingProcessId.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ParentProcessId
The ParentProcessId column in the DeviceProcessEvents table stores the process ID (PID) of the parent process that initiated the current process. To find all child processes spawned by a specific parent process with a known ProcessId, you query the ParentProcessId column for that value. This directly links child processes to their parent, enabling the analyst to trace the malware's execution chain.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
ParentProcessId
Why this is correct
ParentProcessId is the process identifier of the process that created the current process; it directly represents the immediate parent in the process tree. By filtering on this field, an analyst can quickly isolate all child processes spawned by a suspected malware process, enabling lineage-based detection. This is the correct field for defining direct process ancestry, unlike ProcessId or LogonId.
- ✗
InitiatingProcessId
Why it's wrong here
InitiatingProcessId, as defined in many telemetry schemas, points to the original root process that started an entire activity chain, not necessarily the direct creator of a given process. For example, if an Office document launches PowerShell, which then runs cmd.exe, InitiatingProcessId on cmd.exe may reference the Office process rather than PowerShell. Relying on it to filter immediate children would skip intermediate processes and could overinclude processes in the same chain, making it inappropriate for direct parent-child analysis.
- ✗
ProcessId
Why it's wrong here
ProcessId identifies the current process itself, the subject under investigation, rather than its origin. Querying by ProcessId returns the process's own row and says nothing about which process created it or which processes it has spawned. Therefore it cannot be used to reconstruct parent-child relationships; you would need a separate field such as ParentProcessId to move up the process tree.
- ✗
LogonId
Why it's wrong here
LogonId is a numerical identifier for a Windows logon session, representing a security context under which processes run, not an individual process. A single logon session typically hosts many processes and services, so it provides no information about process ancestry or which process spawned another. Using LogonId would group together all processes in a session, but it would not differentiate between a process and its children.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.