mediumMultiple Select
SC-200 Practice Question: An analyst is investigating a ransomware outbreak…
An analyst is investigating a ransomware outbreak using Microsoft 365 Defender Advanced Hunting. They need to find all devices where a file with the extension '.locked' was created within one hour after a known malicious process (e.g., 'ransomware.exe') was executed on the same device. Which two tables should be joined in the query? (Choose 2.)
⚠ Common exam trap
The trap here is that candidates may mistakenly choose DeviceNetworkEvents thinking network activity is key, but the question specifically requires file creation events, which only DeviceFileEvents provides.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DeviceProcessEvents
DeviceProcessEvents is correct because it logs process creation events, including the execution of 'ransomware.exe'. This table is essential to identify the timestamp and device where the malicious process ran, which serves as the starting point for the time-bound investigation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
DeviceProcessEvents
Why this is correct
DeviceProcessEvents is the correct table because advanced hunting in Microsoft 365 Defender stores process creation and launch activity here, including fields such as ProcessCommandLine, ParentProcessId, and Timestamp. When ransomware executes, its malicious executable appears as a new process event, and analysts can trace process lineage to identify the initial access vector and scope of execution. This table is the primary source for determining which process launched the ransomware and what actions it performed on the host.
- ✗
DeviceNetworkEvents
Why it's wrong here
DeviceNetworkEvents logs network connection attempts, including local and remote IP addresses, ports, and protocol details, but it lacks the file system and process creation attributes needed to see the executable itself. While a ransomware outbreak may generate connections to a command-and-control server or internal shares, those events occur after execution and do not directly reveal which process created the malicious file or when it was spawned. To identify the actual ransomware binary, an analyst must pivot to process creation and file event tables rather than relying on network telemetry alone.
- ✓
DeviceFileEvents
Why this is correct
DeviceFileEvents is also correct because it records when a file is created, renamed, modified, or deleted on a device, making it essential for spotting ransomware's encryption behavior as normal files are overwritten or get new extensions. During an outbreak, this table can show the appearance of the malicious payload (such as an EXE or script dropped to disk) and the rapid modification of user documents, providing critical evidence of lateral movement and data loss. Although it does not contain process execution details, it complements DeviceProcessEvents by documenting the on-disk artifacts and the specific files impacted by encryption.
- ✗
DeviceRegistryEvents
Why it's wrong here
DeviceRegistryEvents captures modifications to the Windows Registry, such as new Run keys, service entries, or AppInit_DLLs, which are used for persistence or defense evasion. While ransomware often writes registry values to establish persistence, the creation of the malicious executable itself is not a registry event, so this table cannot directly identify the ransomware binary or the moment it was executed. An analyst would query this table only after finding the process or file evidence to establish how the malware maintained a foothold.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.