SC-200 Perform threat hunting Practice Question
During a threat hunt in Microsoft Sentinel, you want to find hosts that began communicating with a newly registered domain shortly after a suspicious process executed on the same host. Your data is in DeviceProcessEvents and DeviceNetworkEvents. Which approach best correlates process execution and subsequent network connections on the same device within a time window?
⚠ Common exam trap
The trap here is joining on process name or remote IP, which are not unique identifiers, instead of using DeviceId with an explicit time-window condition.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Join DeviceProcessEvents and DeviceNetworkEvents on DeviceId with a time-window condition that places the network event after the process event
Correlating execution to later network activity requires a device-scoped join with a temporal constraint. Joining on DeviceId and requiring the network timestamp to be later than the process timestamp, within a bounded window, preserves causality and keeps unrelated hosts out of the result, which is what the hunt hypothesis needs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Join DeviceProcessEvents and DeviceNetworkEvents on DeviceId with a time-window condition that places the network event after the process event
Why this is correct
Joining on DeviceId and constraining the network timestamp to fall shortly after the process timestamp links the suspicious execution to the outbound connection on the same host. This preserves the causal sequence the hunt hypothesis depends on and avoids correlating unrelated activity.
- ✗
Union DeviceProcessEvents and DeviceNetworkEvents and filter by timestamp
Why it's wrong here
A union appends the two schemas into one result set without linking rows. Filtering by timestamp alone cannot establish that a specific process on a specific device caused a particular network connection, so the causal relationship is lost.
- ✗
Summarize each table by DeviceId and compare the resulting counts
Why it's wrong here
Aggregating counts per device discards the individual process and network events along with their timestamps. You would see that a device had both activity types but could not determine whether the connection followed the suspicious execution.
- ✗
Join the two tables on the process name and remote IP address
Why it's wrong here
Process names are not unique and remote IPs change constantly, so joining on these fields produces false correlations across different hosts. It also fails when the process name is generic, such as svchost.exe, and ignores the device identity entirely.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.