Courseiva
mediumMultiple Choice

SC-200 Practice Question: A security analyst is investigating a ransomware…

A security analyst is investigating a ransomware incident in Microsoft 365 Defender. The analyst wants to view all processes that initiated outbound network connections to known malicious IPs on a specific device. Which advanced hunting table should the analyst query?

⚠ Common exam trap

Microsoft often tests the distinction between process creation events (DeviceProcessEvents) and network connection events (DeviceNetworkEvents), trapping candidates who assume that process logs include network activity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

DeviceNetworkEvents

The DeviceNetworkEvents table in Microsoft 365 Defender captures network connection events, including outbound connections to IP addresses, ports, and protocols. To investigate processes that initiated outbound connections to known malicious IPs on a specific device, this table provides the necessary data, such as the initiating process ID, remote IP, and port. The DeviceProcessEvents table only logs process creation events, not network activity, making it unsuitable for this query.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    DeviceNetworkEvents

    Why this is correct

    The correct choice is DeviceNetworkEvents because this table captures outbound network connection attempts and established connections, recording the destination IP, port, protocol, and the initiating process's ID and name. In a ransomware investigation, this table reveals the process that communicates with attacker-controlled infrastructure, enabling the analyst to map lateral movement or identify the ransomware's beaconing behavior. Unlike process creation logs, this table specifically correlates each connection to the process that made it, which is essential to confirm the malicious process's network activity.

  • ✗

    DeviceProcessEvents

    Why it's wrong here

    DeviceProcessEvents records process creation events, such as the executable path, command line, and parent process, but it does not contain any fields for destination IP addresses, ports, or connection state. Even if you identify the ransomware process here, you cannot determine which external hosts it contacted without joining to the network table. Thus, by itself, it is insufficient for investigating the ransomware's outbound network behavior.

  • ✗

    DeviceFileEvents

    Why it's wrong here

    DeviceFileEvents logs file system activity such as creating, modifying, deleting, or renaming files, and includes metadata like file hash, path, and the process involved. While it could show the ransomware's encrypted file marker or the initial payload dropping, it contains zero data about IP addresses, ports, or connection protocols. Because the investigation centers on identifying which process made network connections, file events are outside the scope.

  • ✗

    DeviceRegistryEvents

    Why it's wrong here

    DeviceRegistryEvents records changes to the Windows registry, such as adding a Run key for persistence or altering security identifiers, but it has no fields for network destinations, ports, or connection status. While malware might modify registry entries to achieve persistence or disable defenses, that activity is a separate telemetry source from network communication. Therefore, it cannot be used to track the ransomware's network connections, making it an incorrect choice.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.