Courseiva
Perform threat hunting →hardMultiple Choice

SC-200 Perform threat hunting Practice Question

Exhibit

Refer to the exhibit.
```json
{
  "displayName": "Suspicious PowerShell Execution",
  "description": "Detects PowerShell launching from unusual parent processes",
  "query": "DeviceProcessEvents | where FileName == 'powershell.exe' and ParentFileName in~ ('explorer.exe', 'winword.exe', 'excel.exe')",
  "tactics": ["Execution"],
  "techniques": ["T1059.001"],
  "severity": "Medium"
}
```

Refer to the exhibit. A custom detection rule in Microsoft Sentinel uses this JSON definition. An analyst notices that the rule is generating alerts for legitimate administrative scripts launched from File Explorer. What is the best way to reduce false positives while retaining detection of malicious Office-based PowerShell launches?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add an additional filter to exclude PowerShell executions from specific administrative user accounts

Adding conditions to exclude known administrative scenarios (e.g., specific user accounts) reduces false positives without removing the parent process filter entirely. Option B is wrong because removing the parent process filter would broaden detection, likely increasing false positives. Option C is wrong because lowering severity does not reduce false positives. Option D is wrong because increasing time range does not help.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Add an additional filter to exclude PowerShell executions from specific administrative user accounts

    Why this is correct

    Excluding known admin accounts helps reduce noise while keeping detection for other users.

  • ✗

    Increase the query time range to 30 days

    Why it's wrong here

    Time range does not affect false positives in this context.

  • ✗

    Change the severity to Informational to suppress alerts

    Why it's wrong here

    Severity change does not reduce false positives; it only changes alert classification.

  • ✗

    Remove the parent process filter and rely only on FileName == 'powershell.exe'

    Why it's wrong here

    This would increase false positives by detecting all PowerShell launches.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.