hardMultiple Choice
SC-200 Practice Question: An analyst is using advanced hunting in Microsoft…
An analyst is using advanced hunting in Microsoft 365 Defender. A device made outbound RDP connections shortly after a suspicious PowerShell process started. Which join is most useful to identify the initiating process for those network connections?
⚠ Common exam trap
Many exam-takers choose a join involving cloud or email tables (A, B, C) because they focus on the 'suspicious PowerShell' aspect, forgetting that the question specifically asks for the initiating process of network connections, which requires device-level process and network event correlation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Join DeviceNetworkEvents with DeviceProcessEvents by device and process identifiers/time window
It joins DeviceNetworkEvents (which contain outbound RDP connection details) with DeviceProcessEvents (which contain process creation data like the suspicious PowerShell process) using device ID, process ID, and a time window. This join allows the analyst to directly correlate the network connection to the initiating process, identifying whether the PowerShell process spawned the RDP connection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Join EmailEvents with UrlClickEvents
Why it's wrong here
EmailEvents and UrlClickEvents capture mail delivery, message routing, and user URL click verdicts, but they contain no endpoint process identifiers such as PID, process GUID, or local process creation timestamps. RDP initiation is a network connection event whose initiating process is recorded in DeviceNetworkEvents and DeviceProcessEvents, not in email or URL click telemetry, so this join cannot identify the process that started the RDP session.
- ✗
Join IdentityInfo with SecureScoreControls
Why it's wrong here
IdentityInfo stores Microsoft Entra ID/on-premises identity metadata such as account names and group memberships, while SecureScoreControls contains security control configuration assessments. Neither table includes process creation or network connection records, so joining them would produce no telemetry about the local endpoint process or the outbound RDP connection. This combination addresses account posture, not the process-level forensic trace needed to attribute the RDP activity.
- ✗
Join CloudAppEvents with AlertEvidence only
Why it's wrong here
CloudAppEvents logs user activities in SaaS applications and AlertEvidence may hold alert-related entities, but neither table provides a comprehensive mapping of endpoint network connections to local process creation. RDP initiation is an endpoint event requiring DeviceNetworkEvents and DeviceProcessEvents to correlate the destination IP with the initiating process. Relying on cloud app activity and alert evidence alone would leave a gap in the process chain that initiated the remote desktop connection.
- ✓
Join DeviceNetworkEvents with DeviceProcessEvents by device and process identifiers/time window
Why this is correct
DeviceNetworkEvents records outbound and inbound network connections, including InitiatingProcessId and InitiatingProcessFileName, while DeviceProcessEvents captures process creation with ProcessId, ParentProcessId, CreationTime, and command-line arguments. Joining these tables on DeviceId and ProcessId/InitiatingProcessId, with a time window aligned to the process creation timestamp, maps the RDP network connection to the exact process (e.g., mstsc.exe) and its parent, enabling full attribution of the RDP session.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.