Courseiva
Perform threat hunting →mediumMultiple Choice

SC-200 Perform threat hunting Practice Question

During a threat hunt in Microsoft Sentinel, you want to find hosts that began communicating with a newly registered domain shortly after a suspicious process executed on the same host. Your data is in DeviceProcessEvents and DeviceNetworkEvents. Which approach best correlates process execution and subsequent network connections on the same device within a time window?

⚠ Common exam trap

The trap here is joining on process name or remote IP, which are not unique identifiers, instead of using DeviceId with an explicit time-window condition.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Join DeviceProcessEvents and DeviceNetworkEvents on DeviceId with a time-window condition that places the network event after the process event

Correlating execution to later network activity requires a device-scoped join with a temporal constraint. Joining on DeviceId and requiring the network timestamp to be later than the process timestamp, within a bounded window, preserves causality and keeps unrelated hosts out of the result, which is what the hunt hypothesis needs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Join DeviceProcessEvents and DeviceNetworkEvents on DeviceId with a time-window condition that places the network event after the process event

    Why this is correct

    Joining on DeviceId and constraining the network timestamp to fall shortly after the process timestamp links the suspicious execution to the outbound connection on the same host. This preserves the causal sequence the hunt hypothesis depends on and avoids correlating unrelated activity.

  • ✗

    Union DeviceProcessEvents and DeviceNetworkEvents and filter by timestamp

    Why it's wrong here

    A union appends the two schemas into one result set without linking rows. Filtering by timestamp alone cannot establish that a specific process on a specific device caused a particular network connection, so the causal relationship is lost.

  • ✗

    Summarize each table by DeviceId and compare the resulting counts

    Why it's wrong here

    Aggregating counts per device discards the individual process and network events along with their timestamps. You would see that a device had both activity types but could not determine whether the connection followed the suspicious execution.

  • ✗

    Join the two tables on the process name and remote IP address

    Why it's wrong here

    Process names are not unique and remote IPs change constantly, so joining on these fields produces false correlations across different hosts. It also fails when the process name is generic, such as svchost.exe, and ignores the device identity entirely.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.