Courseiva
Perform threat hunting →hardMultiple Choice

SC-200 Perform threat hunting Practice Question

During a threat hunt, you discover a suspicious PowerShell command that decoded a base64 string and executed a script. Which Microsoft Defender for Endpoint advanced hunting table should you query to find the decoded command line?

⚠ Common exam trap

SC-200 often tests the distinction between process-level telemetry (DeviceProcessEvents) and network or identity telemetry, causing candidates to choose DeviceEvents or DeviceNetworkEvents when the question asks for command-line details.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

DeviceProcessEvents

DeviceProcessEvents in Microsoft Defender for Endpoint advanced hunting contains process creation events, including the full command line used to launch processes. Since the suspicious PowerShell command executed a script, the decoded command line would be captured in this table under the ProcessCommandLine column.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    IdentityLogonEvents

    Why it's wrong here

    IdentityLogonEvents is an advanced hunting table that records authentication and sign-in activity — such as successful or failed logon attempts, logon types, and authentication methods — from Active Directory and Microsoft Entra ID. It contains no process execution telemetry and no column for command-line arguments, so it cannot reveal what a PowerShell process actually executed. Even if the suspicious PowerShell session initiated an identity-related action, the command line itself would not appear here, making this table irrelevant for the hunt.

  • ✓

    DeviceProcessEvents

    Why this is correct

    DeviceProcessEvents is the correct table because it captures process creation events on endpoints, and its ProcessCommandLine column stores the exact command line used to launch each process. This includes the PowerShell executable path, individual arguments, flags like -EncodedCommand or -ExecutionPolicy Bypass, and any obfuscated script text. The table also provides process ID, parent process, and initiating process command line, which are crucial for gaining full context on the suspicious PowerShell invocation during a threat hunt.

  • ✗

    DeviceNetworkEvents

    Why it's wrong here

    DeviceNetworkEvents records network-level activity, including connections to IPs and ports, DNS resolutions, and connection directions, but it deliberately excludes process command-line arguments. While it might show that a PowerShell process initiated outbound traffic, it will not reveal the specific PowerShell script or the arguments that were executed. Investigators cannot use this table to retrieve the command line that triggered the threat, so it cannot satisfy the need to inspect the suspicious PowerShell command.

  • ✗

    DeviceEvents

    Why it's wrong here

    DeviceEvents is a broad telemetry table in advanced hunting that captures on-device security events such as antivirus detections, file system changes, and registry modifications, but its schema does not include a ProcessCommandLine column. It may reference a PowerShell executable in a security alert, yet it lacks the granular detail of the actual command-line arguments passed to the process. Because the threat hunt specifically requires analyzing the PowerShell command line, DeviceEvents does not provide the necessary data depth, making DeviceProcessEvents the only suitable choice.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.