SC-200 Perform threat hunting Practice Question
During threat hunting, you identify a suspicious PowerShell process that executed encoded commands. Which Microsoft Defender XDR hunting capability would best help you trace the parent process and command-line arguments across the enterprise?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Advanced hunting
Advanced hunting in Microsoft Defender XDR uses KQL queries to trace parent processes and command-line arguments across devices, enabling detailed investigation of suspicious PowerShell activity. Option A is incorrect because automated investigation and response focuses on containment and remediation, not deep forensic tracing. Option B is incorrect because threat analytics provides threat intelligence and vulnerability information, not raw process event data. Option C is incorrect because device inventory shows device configurations and status, but lacks process lineage and command-line details.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Automated investigation and response
Why it's wrong here
Automated investigation and response is an orchestration engine that reacts only to generated alerts from Microsoft 365 Defender, such as malware detections, not to ad-hoc hunting queries. A manually observed suspicious PowerShell script will not trigger investigation and response unless a corresponding alert is raised. Even then, its purpose is to run response actions on affected devices, not to query historical process execution events or reconstruct process lineage. For tracing that PowerShell invocation back through its parent chain, Advanced Hunting is the required data exploration surface.
- ✗
Threat analytics
Why it's wrong here
Threat analytics is a curated intelligence view in Microsoft 365 Defender that explains active threat groups, vulnerabilities, and suggested mitigations; it does not serve raw telemetry or event-level data. It may describe how PowerShell is abused by a specific actor, but it cannot show which devices actually executed a given suspicious PowerShell command. Therefore, it can inform the hunt but cannot validate or trace the suspicious process encountered in the environment.
- ✗
Device inventory
Why it's wrong here
Device inventory presents a consolidated asset list with endpoint metadata like device names, operating system, onboarding status, and relative risk. It does not contain process-level data, command-line arguments, or execution-history tables. As a result, you cannot use device inventory to understand how a suspicious PowerShell process was spawned, what it ran, or what the process lineage looks like across the fleet.
- ✓
Advanced hunting
Why this is correct
Advanced Hunting is the Microsoft 365 Defender tool purpose-built for proactively querying across deep time series and event tables via KQL, including DeviceProcessEvents, DeviceEvents, and associated network/file events. With schema-aware queries such as process parent-child joins, an analyst can pivot from a suspicious PowerShell process to its parent chain, command-line, file hashes, and related lateral-movement indicators. This makes it the correct surface for ad-hoc threat hunting and validating a specific suspicious process observed in the environment.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.