SC-200 Respond to security incidents Practice Question
A security team is investigating a ransomware incident that encrypted files on several Windows servers. Microsoft Defender for Endpoint detected the ransomware but the initial infection vector is unknown. Which KQL query in Microsoft Sentinel would BEST identify the initial process that executed the ransomware?
⚠ Common exam trap
Watch out — candidates often choose Option D (DeviceEvents with RansomwareDetection) because it directly shows the detection event, but it lacks the parent process information needed to identify the initial infection vector, which is the specific requirement of the question.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DeviceProcessEvents | where FileName contains 'ransomware.exe' | project DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine, Timestamp
DeviceProcessEvents captures process creation events, and by filtering for the ransomware executable and projecting the InitiatingProcessFileName and InitiatingProcessCommandLine, you can trace back to the parent process that launched the ransomware. This directly identifies the initial infection vector, which is the core goal of the investigation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
DeviceNetworkEvents | where RemoteUrl contains 'malicious' | project DeviceName, RemoteIP, Timestamp
Why it's wrong here
This query returns only network connection records where the remote URL string contains 'malicious'; it does not include process creation telemetry, so it cannot identify the parent process that spawned the ransomware or the command line that executed it. Network events may show outbound beaconing to a command-and-control server after infection, but they are not the initial infection vector and miss the local execution chain entirely. Relying on a URL substring filter is also fragile because ransomware often uses IP addresses, legitimately hosted domains, or encrypted DNS, making this approach blind to the actual detonation point.
- ✗
DeviceFileEvents | where FileName contains 'ransomware.exe' | project DeviceName, ActionType, Timestamp
Why it's wrong here
DeviceFileEvents captures file-system actions such as creation, modification, or deletion, but the schema for this table does not include the parent-process relationship that is essential for tracing a ransomware infection. Seeing a file named 'ransomware.exe' does not prove that it was ever executed, nor does it reveal whether it was dropped by a macro, a PowerShell script, a remote SMB copy, or an exploit delivery. The ActionType column only indicates the file operation that occurred, not the initiating process executable or its command-line arguments, so the true infection path remains hidden and the query cannot support root-cause analysis.
- ✓
DeviceProcessEvents | where FileName contains 'ransomware.exe' | project DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine, Timestamp
Why this is correct
The DeviceProcessEvents table records actual process creation events on the endpoint, and this query filters for any process whose file name is 'ransomware.exe' while projecting the initiating process file name and its command line. That parent relationship is the critical forensic evidence: it shows which executable (for example msiexec.exe, rundll32.exe, or a malicious PowerShell) launched the ransomware, enabling the security team to trace back to the initial access vector. Including the timestamp supports chronological reconstruction of the infection, which is the core goal of the incident response investigation.
- ✗
DeviceEvents | where ActionType == 'RansomwareDetection' | project DeviceName, Timestamp
Why it's wrong here
Filtering DeviceEvents by ActionType == 'RansomwareDetection' returns detection alerts that security products have already correlated, but these are not raw process telemetry. Such events may confirm that ransomware was detected on the device, yet they do not expose the parent process, the child process command line, or other forensic details needed to identify the attack's entry point and scope. Because this query projects only DeviceName and Timestamp, any process-lineage or threat-intel columns are discarded, leaving the team without actionable information about the process tree that led to the ransomware execution.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.