mediumMultiple Choice
SC-200 Practice Question: In Microsoft 365 Defender, an analyst is…
In Microsoft 365 Defender, an analyst is investigating an incident involving a malicious script. The analyst wants to see the command-line arguments executed by the script on a specific device. Which Advanced Hunting table should the analyst query?
⚠ Common exam trap
Many candidates confuse DeviceProcessEvents with DeviceEvents, assuming the latter includes all process-related data, but DeviceEvents is a catch-all for miscellaneous events and does not contain the ProcessCommandLine column.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DeviceProcessEvents
The DeviceProcessEvents table in Advanced Hunting captures process creation events, including the command-line arguments used to execute a process. Since the analyst needs to see the command-line arguments executed by a malicious script on a specific device, querying DeviceProcessEvents is the correct approach because it records the ProcessCommandLine column for each process creation event.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
DeviceProcessEvents
Why this is correct
DeviceProcessEvents is the advanced hunting table that records process creation events, and it includes the ProcessCommandLine field, which captures the full command-line string passed to the newly created process. When investigating suspicious execution, this table lets an analyst see exact arguments such as encoded PowerShell commands or unusual flags, providing direct evidence of the process's intended behavior. It is the authoritative source for command-line telemetry in Microsoft 365 Defender.
- ✗
DeviceNetworkEvents
Why it's wrong here
DeviceNetworkEvents logs network connection attempts and established sessions, storing details like source and destination IP addresses, ports, protocols, and the responsible process ID and name. It does not include the process command line or the arguments used when the process was launched, so it cannot reveal execution parameters. While this table can show the network communication that results from a process, it must be joined with DeviceProcessEvents to understand how that process was invoked.
- ✗
DeviceFileEvents
Why it's wrong here
DeviceFileEvents tracks file system activity including creation, modification, deletion, and renaming, and records the file path and the process that performed the operation. It does not store the command-line arguments that caused those file operations, such as the specific switches used by a script or utility. This table is useful for identifying artifacts written to disk, but it lacks the execution context needed to determine why or how the process was started, which is found only in DeviceProcessEvents.
- ✗
DeviceEvents
Why it's wrong here
DeviceEvents is a heterogeneous table that aggregates many OS-level activities, such as scheduled task creation, WMI execution, process access, and other security-relevant events. Although some event types in this table may occasionally embed a limited command line in their fields, it is not designed to systematically capture process command-line arguments for every process execution. For comprehensive and reliable command-line analysis, the analyst must query DeviceProcessEvents, which provides structured and consistent ProcessCommandLine data across all process creations.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SC-200
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A security analyst is investigating an incident in Microsoft 365 Defender that involves a user who clicked a phishing link. The analyst wants to find all processes executed on the user's device immediately after the email was opened. Which advanced hunting table should the analyst query to obtain process creation events with timestamps relative to the email event?
medium- ✓ A.DeviceProcessEvents
- B.EmailEvents
- C.DeviceNetworkEvents
- D.IdentityLogonEvents
Why A: DeviceProcessEvents is the correct table because it stores process creation events (including image name, command line, and timestamp) for all devices onboarded to Microsoft Defender for Endpoint. By querying this table with a time range starting immediately after the email event (identified from EmailEvents), the analyst can correlate the phishing click with subsequent process executions on the user's device.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.