Courseiva
mediumMultiple Choice

SC-200 Practice Question: In Microsoft 365 Defender, an analyst is…

In Microsoft 365 Defender, an analyst is investigating an incident involving a malicious script. The analyst wants to see the command-line arguments executed by the script on a specific device. Which Advanced Hunting table should the analyst query?

⚠ Common exam trap

Many candidates confuse DeviceProcessEvents with DeviceEvents, assuming the latter includes all process-related data, but DeviceEvents is a catch-all for miscellaneous events and does not contain the ProcessCommandLine column.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

DeviceProcessEvents

The DeviceProcessEvents table in Advanced Hunting captures process creation events, including the command-line arguments used to execute a process. Since the analyst needs to see the command-line arguments executed by a malicious script on a specific device, querying DeviceProcessEvents is the correct approach because it records the ProcessCommandLine column for each process creation event.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    DeviceProcessEvents

    Why this is correct

    DeviceProcessEvents is the advanced hunting table that records process creation events, and it includes the ProcessCommandLine field, which captures the full command-line string passed to the newly created process. When investigating suspicious execution, this table lets an analyst see exact arguments such as encoded PowerShell commands or unusual flags, providing direct evidence of the process's intended behavior. It is the authoritative source for command-line telemetry in Microsoft 365 Defender.

  • ✗

    DeviceNetworkEvents

    Why it's wrong here

    DeviceNetworkEvents logs network connection attempts and established sessions, storing details like source and destination IP addresses, ports, protocols, and the responsible process ID and name. It does not include the process command line or the arguments used when the process was launched, so it cannot reveal execution parameters. While this table can show the network communication that results from a process, it must be joined with DeviceProcessEvents to understand how that process was invoked.

  • ✗

    DeviceFileEvents

    Why it's wrong here

    DeviceFileEvents tracks file system activity including creation, modification, deletion, and renaming, and records the file path and the process that performed the operation. It does not store the command-line arguments that caused those file operations, such as the specific switches used by a script or utility. This table is useful for identifying artifacts written to disk, but it lacks the execution context needed to determine why or how the process was started, which is found only in DeviceProcessEvents.

  • ✗

    DeviceEvents

    Why it's wrong here

    DeviceEvents is a heterogeneous table that aggregates many OS-level activities, such as scheduled task creation, WMI execution, process access, and other security-relevant events. Although some event types in this table may occasionally embed a limited command line in their fields, it is not designed to systematically capture process command-line arguments for every process execution. For comprehensive and reliable command-line analysis, the analyst must query DeviceProcessEvents, which provides structured and consistent ProcessCommandLine data across all process creations.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SC-200

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A security analyst is investigating an incident in Microsoft 365 Defender that involves a user who clicked a phishing link. The analyst wants to find all processes executed on the user's device immediately after the email was opened. Which advanced hunting table should the analyst query to obtain process creation events with timestamps relative to the email event?

medium
  • ✓ A.DeviceProcessEvents
  • B.EmailEvents
  • C.DeviceNetworkEvents
  • D.IdentityLogonEvents

Why A: DeviceProcessEvents is the correct table because it stores process creation events (including image name, command line, and timestamp) for all devices onboarded to Microsoft Defender for Endpoint. By querying this table with a time range starting immediately after the email event (identified from EmailEvents), the analyst can correlate the phishing click with subsequent process executions on the user's device.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.