Courseiva
hardMultiple Select

SC-200 Practice Question: An analyst writes an advanced hunting query to…

An analyst writes an advanced hunting query to investigate a suspicious executable that initiated outbound connections. Which two Microsoft 365 Defender tables are most relevant? (Choose 2.)

⚠ Common exam trap

The trap here is that candidates may mistakenly choose EmailAttachmentInfo thinking the executable arrived via email, but the question focuses on the executable's outbound connections, not its delivery method.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

DeviceProcessEvents.

DeviceProcessEvents is correct because it records process creation events, including the executable that initiated the outbound connection. By querying this table, you can identify the suspicious executable's name, command line, and parent process, which is essential for tracing the origin of the malicious activity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    DeviceProcessEvents.

    Why this is correct

    DeviceProcessEvents is the correct table because it records process creation events, including the executable path, command-line arguments, and process ID (which appears as InitiatingProcessId for child processes). In an advanced hunting query, this table supplies the process execution side of the evidence chain, enabling you to join with network events on device ID and time window to determine exactly which process was launched before a suspicious connection was made.

  • ✓

    DeviceNetworkEvents.

    Why this is correct

    DeviceNetworkEvents is correct for capturing the actual network activity on an endpoint, including outbound and inbound connections, remote IP and port, protocol, and the process that initiated the connection. This table directly provides the network visibility needed to correlate with process creation records from DeviceProcessEvents, allowing you to see whether a given process generated the network connection you are investigating.

  • ✗

    EmailAttachmentInfo.

    Why it's wrong here

    EmailAttachmentInfo is wrong because it is part of the email and collaboration hunting tables, containing metadata such as file name, SHA256 hash, and file size for attachments on emails processed by Exchange Online or Microsoft Defender for Office 365. While it supports phishing investigations, it does not include process creation events or network connection events, so it cannot be used to directly correlate process execution with outbound or inbound network traffic on a device.

  • ✗

    IdentityInfo.

    Why it's wrong here

    IdentityInfo is wrong for this investigation because it stores user account metadata, such as account name, domain, and security identifiers, sourced from Microsoft Entra ID and on-premises directories. It is useful for mapping an alert to a user's identity or contextualizing access, but it lacks any process execution or network connection log entries, so it is entirely irrelevant for correlating a process to network activity.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.