Hunt for Malicious Script by Hash Across Devices in Microsoft Sentinel
During a threat hunt, an analyst discovers a PowerShell script that was executed on multiple servers in the environment. The script connects to an external IP address and downloads a payload. The analyst wants to find all other servers that may have been compromised by the same script. What is the most efficient way to search for this across the environment?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use the DeviceProcessEvents table in Microsoft Defender for Endpoint advanced hunting to search for the script's SHA256 hash or command line pattern
It leverages Microsoft Defender for Endpoint's advanced hunting to centrally search for the script's SHA256 hash or command line pattern across all endpoints. Option A is incorrect because Sysmon may not be installed on all servers, and querying each server individually is inefficient. Option B is incorrect because network logs only show network connections and do not provide process execution details. Option D is incorrect because querying Event ID 4104 requires enabling PowerShell script block logging and accessing each server individually, which is less efficient than centralized hunting.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use Sysmon Event ID 1 (process creation) to find PowerShell executions
Why it's wrong here
Sysmon Event ID 1 can record process creation, but it requires Sysmon to be installed on each server and does not centralize the search. It is less efficient than using Defender for Endpoint advanced hunting.
- ✗
Review the network logs from the firewall for connections to the external IP
Why it's wrong here
Firewall logs only show that a connection to the external IP occurred; they cannot tie it to the specific PowerShell script or reveal other execution artefacts. It is tempting because the script contacts that IP, and it would be correct for identifying every host with outbound traffic to a known malicious address.
- ✓
Use the DeviceProcessEvents table in Microsoft Defender for Endpoint advanced hunting to search for the script's SHA256 hash or command line pattern
Why this is correct
The DeviceProcessEvents table records process creation events, including command lines and file hashes, across all onboarded devices. Searching by the script's SHA256 hash or command-line pattern identifies every server where the same PowerShell execution occurred, directly satisfying the requirement to find other compromised servers efficiently.
- ✗
Query the Windows Event Log for Event ID 4104 (PowerShell script block logging) on each server
Why it's wrong here
Querying Event ID 4104 requires touching every server individually, which does not scale across a fleet and misses hosts where script block logging is disabled. It is tempting because it captures the script's actual content, and it would be correct for deep forensic analysis of one known compromised machine.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.