hardMultiple Choice
SC-200 Practice Question: An analyst is creating a custom detection rule in…
An analyst is creating a custom detection rule in Microsoft 365 Defender to detect lateral movement. The rule should trigger when a device (DeviceA) connects to another device (DeviceB) via SMB (port 445) and, within 5 minutes, a scheduled task is created on DeviceB. Which Advanced Hunting query pattern correctly correlates these events across devices?
⚠ Common exam trap
The trap here is that candidates might think `DeviceProcessEvents` is needed to capture the SMB connection (Option B), but SMB is a kernel-mode protocol and not logged as a user-mode process, so `DeviceNetworkEvents` is the correct source for network-level correlation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Join DeviceNetworkEvents (where RemoteIP is DeviceB's IP and RemotePort 445) with DeviceEvents (where ActionType == 'ScheduledTaskCreated' and DeviceId == DeviceB's ID) using a time window of 5 minutes
It uses a `join` between `DeviceNetworkEvents` (filtered for SMB traffic on port 445 from DeviceA to DeviceB) and `DeviceEvents` (filtered for `ActionType == 'ScheduledTaskCreated'` on DeviceB) with a 5-minute time window. This directly correlates the network connection with the subsequent scheduled task creation, which is a classic lateral movement pattern (e.g., PsExec or WMI abuse). The time window ensures the events are causally related within the detection rule's scope.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Join DeviceNetworkEvents (where RemoteIP is DeviceB's IP and RemotePort 445) with DeviceEvents (where ActionType == 'ScheduledTaskCreated' and DeviceId == DeviceB's ID) using a time window of 5 minutes
Why this is correct
This is correct because the rule correlates the two required events in a single chain: an inbound SMB connection from DeviceA to DeviceB's IP on TCP port 445, and a scheduled task created on DeviceB within 5 minutes. Joining DeviceNetworkEvents (filtered to RemoteIP = DeviceB's IP and RemotePort = 445) with DeviceEvents (filtered to ActionType == 'ScheduledTaskCreated' and DeviceId = DeviceB's ID) on DeviceId and a 5-minute time window ties the network attack to the persistence action. This design captures both the lateral movement and the scheduled task creation, making it a precise, high-fidelity detection.
- ✗
Use DeviceProcessEvents to find smb.exe on DeviceA, then join with DeviceFileEvents on DeviceB
Why it's wrong here
This is wrong because DeviceProcessEvents records process creations and command lines, not network connections, so looking for smb.exe on DeviceA would only show that the SMB client process ran, not that it actually connected to DeviceB. DeviceFileEvents logs file creation or modification operations on DeviceB, but scheduled task creation is an action exposed in DeviceEvents via ActionType == 'ScheduledTaskCreated', not in DeviceFileEvents. Ultimately, this query fails to correlate the actual network flow and completely misses the scheduled task event, so it cannot detect the attack chain.
- ✗
Use only DeviceNetworkEvents on DeviceA and DeviceB separately
Why it's wrong here
This is wrong because DeviceNetworkEvents alone only shows network connections and can confirm that DeviceA reached DeviceB on port 445, but it provides no visibility into process-level changes on the target host. Specifically, it cannot capture the creation of a scheduled task, which is recorded in DeviceEvents with ActionType == 'ScheduledTaskCreated'. Without joining to that host action event, the rule would flag benign SMB connections and fail to detect the persistence mechanism, leading to excessive false positives and missed incidents.
- ✗
Use EmailEvents and DeviceEvents on DeviceB
Why it's wrong here
This is wrong because EmailEvents tracks email transport and delivery details, such as sender, recipient, and delivery status, which are irrelevant to an SMB network connection or scheduled task creation. Even though DeviceEvents on DeviceB would capture the ScheduledTaskCreated action, this approach omits DeviceA's inbound network telemetry, so there is no way to link the task creation to a suspicious remote connection. The rule would therefore only see a scheduled task being created in isolation, making it impossible to distinguish malicious lateral movement from routine administrative activity.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.