Courseiva

SC-200 Respond to security incidents Practice Question

During a ransomware incident, an analyst needs to identify which files were encrypted on an endpoint. The endpoint is running Windows and is managed by Microsoft Defender for Endpoint. Which data source should the analyst query in Advanced hunting?

⚠ Common exam trap

Test-takers frequently confuse process-level events (DeviceProcessEvents) with file-level events, assuming that seeing the ransomware process run is sufficient to identify encrypted files, but only DeviceFileEvents provides the actual file paths and timestamps of encryption.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

DeviceFileEvents

DeviceFileEvents is the correct data source because it captures file creation, modification, and deletion events on endpoints. During a ransomware incident, encrypted files are typically created with a new extension or modified in place, and DeviceFileEvents logs these changes, allowing the analyst to identify which files were affected.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    DeviceRegistryEvents

    Why it's wrong here

    DeviceRegistryEvents is incorrect because this table records modifications to Windows Registry keys and values, not file system contents. While ransomware may alter registry values to establish persistence or disable security controls, the act of encrypting user files produces file-level changes such as writes, renames, or extensions; those do not appear in registry logs. Thus, registry events alone cannot directly expose the encryption of data.

  • ✗

    DeviceNetworkEvents

    Why it's wrong here

    DeviceNetworkEvents is incorrect because it captures network connections, DNS resolutions, and other traffic flows, not on-disk data changes. Ransomware encryption is a local file operation that can occur without any network communication, especially when files are already accessible on the endpoint. Network telemetry may show command-and-control traffic or SMB activity, but it does not log the actual modification or encryption of files, making it the wrong table to identify the ransomware's impact.

  • ✗

    DeviceProcessEvents

    Why it's wrong here

    DeviceProcessEvents is incorrect because it logs process creation, execution, and command-line arguments, but not the files that a process creates, writes, or encrypts. Ransomware running as a process would appear here, yet this table lacks the granular file path and operation details needed to see which files were encrypted. Observing a suspicious process is useful, but it does not provide direct evidence of file-level encryption, unlike file event tables.

  • ✓

    DeviceFileEvents

    Why this is correct

    DeviceFileEvents is correct because this table records file system operations such as creation, modification, renaming, and deletion. Ransomware encrypts files by writing encrypted content, often renaming them with new extensions and creating ransom notes, all of which generate file events. Security analysts can query this table for patterns like mass FileModified events from a single process or unusual file extension changes, making it the primary source for directly identifying encryption activity.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.