Courseiva
easyMultiple Choice

SC-200 Practice Question: An analyst wants to find all devices that have…

An analyst wants to find all devices that have run a specific process named 'malware.exe' in the last 24 hours using Microsoft 365 Defender Advanced Hunting. Which table should be the primary source for this query?

⚠ Common exam trap

Test-takers frequently confuse DeviceProcessEvents with DeviceEvents, assuming the latter covers all events, but DeviceEvents is limited to security alerts and audit events, not process creation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

DeviceProcessEvents

The DeviceProcessEvents table in Microsoft 365 Defender Advanced Hunting is the primary source for querying process creation events, including the execution of a specific process name like 'malware.exe'. This table captures process creation and termination events, making it the correct choice for finding devices that have run a specific process within a given time frame.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    DeviceProcessEvents

    Why this is correct

    DeviceProcessEvents is the correct table because it is the dedicated Advanced Hunting schema for process creation events. Filtering on FileName directly yields every device on which that executable was launched, along with exact timestamps and command-line arguments. This table provides the most complete and reliable evidence of process execution, making it the standard resource for hunting a specific binary across the fleet.

  • ✗

    DeviceEvents

    Why it's wrong here

    DeviceEvents is a catch-all table that stores a variety of security event types, including different EventType values, but it is not the canonical source for process creation. While the table may include some process-related events, its schema is less structured for execution hunting, and you would need to filter on EventType to isolate them. In contrast, DeviceProcessEvents specifically exports process creation with all relevant execution details, so choosing DeviceEvents introduces unnecessary ambiguity in a hunt query.

  • ✗

    DeviceFileEvents

    Why it's wrong here

    DeviceFileEvents logs filesystem operations such as file creation, modification, rename, and deletion, not process execution. A process can be run without any corresponding file being created, and conversely, the presence of a file does not indicate that it was ever executed. To identify devices that have actually run a specific executable, you need process creation events, not file lifecycle events.

  • ✗

    DeviceNetworkEvents

    Why it's wrong here

    DeviceNetworkEvents captures network connection attempts, including local and remote IP addresses, ports, and protocols, but it does not record process launches. A specific process may run entirely offline without generating any network activity, so querying this table would undercount the devices that executed it. Its purpose is to investigate communication patterns, not to determine whether a process was executed on a device.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.