SC-200 Perform threat hunting Practice Question
A threat hunter is analyzing a potential advanced persistent threat (APT) that uses living-off-the-land binaries (LOLBins) like certutil.exe to download payloads. The hunter wants to find instances where certutil.exe was used to download files from the internet in the last week. Which KQL query in Microsoft Sentinel would be most effective?
⚠ Common exam trap
SC-200 often tests the ability to distinguish between different LOLBins and their command-line arguments. Candidates might pick a query for a different LOLBin due to familiarity, but the question specifically mentions certutil.exe.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DeviceProcessEvents | where TimeGenerated > ago(7d) | where FileName == "certutil.exe" | where ProcessCommandLine contains "-urlcache" or ProcessCommandLine contains "-split" | project Timestamp, DeviceName, ProcessCommandLine
The query in option C correctly targets certutil.exe and filters for the specific command-line arguments '-urlcache' and '-split', which are commonly used by attackers to download files from the internet. This directly addresses the threat hunter's goal of finding certutil.exe download activity. The other options focus on different LOLBins (powershell.exe, mshta.exe, wscript.exe) that are not mentioned in the scenario.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
DeviceProcessEvents | where TimeGenerated > ago(7d) | where FileName == "powershell.exe" | where ProcessCommandLine contains "-enc" | project Timestamp, DeviceName, ProcessCommandLine
Why it's wrong here
This query filters on powershell.exe with an encoded-command flag, so it never surfaces certutil.exe download activity. It suits hunting obfuscated PowerShell execution, whereas the stem requires matching certutil.exe command lines containing a URL or download verb.
- ✗
DeviceProcessEvents | where TimeGenerated > ago(7d) | where FileName == "mshta.exe" | where ProcessCommandLine contains "http" | project Timestamp, DeviceName, ProcessCommandLine
Why it's wrong here
Filtering on mshta.exe returns HTML Application host activity, not the certutil.exe downloads the hunter asked for, so every matching row is irrelevant. mshta.exe is the right target when hunting malicious .hta execution or URL-based script invocation, which is a different LOLBin technique.
- ✓
DeviceProcessEvents | where TimeGenerated > ago(7d) | where FileName == "certutil.exe" | where ProcessCommandLine contains "-urlcache" or ProcessCommandLine contains "-split" | project Timestamp, DeviceName, ProcessCommandLine
Why this is correct
DeviceProcessEvents captures process creation telemetry from Defender for Endpoint, so filtering FileName for certutil.exe and ProcessCommandLine for the -urlcache or -split switches isolates exactly the LOLBin download behaviour the hunter hypothesised, within the required seven-day window.
- ✗
DeviceProcessEvents | where TimeGenerated > ago(7d) | where FileName == "wscript.exe" | where ProcessCommandLine contains "http" | project Timestamp, DeviceName, ProcessCommandLine
Why it's wrong here
Filtering on wscript.exe returns Windows Script Host activity, not certutil.exe, so the LOLBin named in the scenario is never matched. It is tempting because wscript.exe also downloads payloads via HTTP and belongs in a broader LOLBin hunt; it would be correct had the hunter been investigating script-based downloaders rather than certutil.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.