Courseiva

SC-200 Respond to security incidents Practice Question

An organization uses Microsoft Defender XDR. During an incident investigation, the security team needs to determine if a specific file was executed on any devices in the organization over the past 30 days. They have the file hash. What is the most efficient way to get this information?

⚠ Common exam trap

SC-200 often tests the misconception that the action center or device inventory can be used for historical event searches, when in fact advanced hunting is the only tool designed for proactive, organization-wide threat hunting using raw telemetry.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use advanced hunting to query for file execution events

Advanced hunting in Microsoft Defender XDR provides a Kusto Query Language (KQL) interface to query raw event data across all workloads, including DeviceProcessEvents, DeviceFileEvents, and DeviceEvents. By querying for the specific file hash (e.g., SHA256) in process creation events over the past 30 days, the team can efficiently determine if and where the file executed. This is the most direct and scalable method for historical, organization-wide file execution searches.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use the action center to search for the file

    Why it's wrong here

    The action center in Microsoft 365 Defender centralizes manual and automated response actions such as running antivirus scans, isolating devices, stopping processes, or releasing quarantined files. It is not designed as a query interface for searching historical telemetry, so you cannot look up file execution events by hash there. Its purpose is to track and approve or reject remediation steps, not to investigate where a file has executed.

  • ✓

    Use advanced hunting to query for file execution events

    Why this is correct

    Advanced hunting is the correct tool because it uses Kusto Query Language (KQL) to directly query raw telemetry tables such as DeviceProcessEvents and DeviceFileEvents across all onboarded devices. You can filter by SHA256 file hash to retrieve every execution event, including device, user, command line, and parent process details. This enables a comprehensive, time-bound search for file execution across the entire environment, which aligns with the need to locate all affected systems.

  • ✗

    Review the incident timeline for the file

    Why it's wrong here

    The incident timeline is scoped to a specific incident and displays only alerts and evidence correlated to that incident's entities and time window. It does not provide a global search mechanism for a file hash across all devices, and it will miss occurrences outside the incident's defined scope. For a file-centric cross-environment search, you need a hunting query rather than a timeline constrained to incident context.

  • ✗

    Check the device inventory for the file

    Why it's wrong here

    The device inventory is a management view that lists onboarded devices with properties like last seen, OS version, and risk level, but it has no file-level detail or execution history. It cannot show whether a specific file hash has executed, because it is not an event log. Its function is to help you identify and manage device assets, not to investigate file activity.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.