SC-200 Respond to security incidents Practice Question
During a ransomware incident, an analyst needs to identify which files were encrypted on an endpoint. The endpoint is running Windows and is managed by Microsoft Defender for Endpoint. Which data source should the analyst query in Advanced hunting?
⚠ Common exam trap
Test-takers frequently confuse process-level events (DeviceProcessEvents) with file-level events, assuming that seeing the ransomware process run is sufficient to identify encrypted files, but only DeviceFileEvents provides the actual file paths and timestamps of encryption.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DeviceFileEvents
DeviceFileEvents is the correct data source because it captures file creation, modification, and deletion events on endpoints. During a ransomware incident, encrypted files are typically created with a new extension or modified in place, and DeviceFileEvents logs these changes, allowing the analyst to identify which files were affected.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
DeviceRegistryEvents
Why it's wrong here
DeviceRegistryEvents is incorrect because this table records modifications to Windows Registry keys and values, not file system contents. While ransomware may alter registry values to establish persistence or disable security controls, the act of encrypting user files produces file-level changes such as writes, renames, or extensions; those do not appear in registry logs. Thus, registry events alone cannot directly expose the encryption of data.
- ✗
DeviceNetworkEvents
Why it's wrong here
DeviceNetworkEvents is incorrect because it captures network connections, DNS resolutions, and other traffic flows, not on-disk data changes. Ransomware encryption is a local file operation that can occur without any network communication, especially when files are already accessible on the endpoint. Network telemetry may show command-and-control traffic or SMB activity, but it does not log the actual modification or encryption of files, making it the wrong table to identify the ransomware's impact.
- ✗
DeviceProcessEvents
Why it's wrong here
DeviceProcessEvents is incorrect because it logs process creation, execution, and command-line arguments, but not the files that a process creates, writes, or encrypts. Ransomware running as a process would appear here, yet this table lacks the granular file path and operation details needed to see which files were encrypted. Observing a suspicious process is useful, but it does not provide direct evidence of file-level encryption, unlike file event tables.
- ✓
DeviceFileEvents
Why this is correct
DeviceFileEvents is correct because this table records file system operations such as creation, modification, renaming, and deletion. Ransomware encrypts files by writing encrypted content, often renaming them with new extensions and creating ransom notes, all of which generate file events. Security analysts can query this table for patterns like mass FileModified events from a single process or unusual file extension changes, making it the primary source for directly identifying encryption activity.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.