Courseiva
mediumMultiple Choice

SC-200 Practice Question: A security analyst is investigating an incident…

A security analyst is investigating an incident in Microsoft 365 Defender that involves a user who clicked a phishing link. The analyst wants to find all processes executed on the user's device immediately after the email was opened. Which advanced hunting table should the analyst query to obtain process creation events with timestamps relative to the email event?

⚠ Common exam trap

It's easy for candidates to confuse the table that stores the email event (EmailEvents) with the table that stores the resulting process activity (DeviceProcessEvents), forgetting that process creation data is only in the endpoint-specific table.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

DeviceProcessEvents

DeviceProcessEvents is the correct table because it stores process creation events (including image name, command line, and timestamp) for all devices onboarded to Microsoft Defender for Endpoint. By querying this table with a time range starting immediately after the email event (identified from EmailEvents), the analyst can correlate the phishing click with subsequent process executions on the user's device.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    DeviceProcessEvents

    Why this is correct

    DeviceProcessEvents is the correct table because it captures process creation events on endpoints, including the executable name, command line, parent process, and timestamp. When investigating a phishing click, this table lets you determine exactly which process was spawned (e.g., a script from a downloaded attachment) and whether it initiated further malicious activity. Without this telemetry, there is no direct evidence that a suspicious executable was run on the device.

  • ✗

    EmailEvents

    Why it's wrong here

    EmailEvents contains metadata about email delivery, such as the sender, recipient, subject, and delivery status, but it does not include any device-level process activity. While this table is valuable for identifying the phishing message itself and the user who received it, it cannot show what happened after the user clicked the link or opened the attachment. To confirm a process was executed, you must query DeviceProcessEvents instead.

  • ✗

    DeviceNetworkEvents

    Why it's wrong here

    DeviceNetworkEvents records network connections initiated by processes, including source and destination IP addresses, ports, and protocols. Seeing a network connection to a known malicious IP is suggestive but not proof that a process was created; the connection could originate from an existing benign process that was abused. You need DeviceProcessEvents to confirm that a new process (e.g., a downloaded payload) was actually executed on the endpoint.

  • ✗

    IdentityLogonEvents

    Why it's wrong here

    IdentityLogonEvents captures authentication events for user identities, such as successful or failed logons, authentication methods, and risk levels. This table can tell you that a user's account was used to log on, but it contains zero information about processes running on the device. Process creation is recorded in DeviceProcessEvents, a separate telemetry source, so IdentityLogonEvents cannot provide evidence of execution after a phishing click.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.