SC-200 Perform threat hunting Practice Question
Exhibit
Refer to the exhibit.
```json
{
"displayName": "Suspicious PowerShell Execution",
"description": "Detects PowerShell launching from unusual parent processes",
"query": "DeviceProcessEvents | where FileName == 'powershell.exe' and ParentFileName in~ ('explorer.exe', 'winword.exe', 'excel.exe')",
"tactics": ["Execution"],
"techniques": ["T1059.001"],
"severity": "Medium"
}
```Refer to the exhibit. A custom detection rule in Microsoft Sentinel uses this JSON definition. An analyst notices that the rule is generating alerts for legitimate administrative scripts launched from File Explorer. What is the best way to reduce false positives while retaining detection of malicious Office-based PowerShell launches?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add an additional filter to exclude PowerShell executions from specific administrative user accounts
Adding conditions to exclude known administrative scenarios (e.g., specific user accounts) reduces false positives without removing the parent process filter entirely. Option B is wrong because removing the parent process filter would broaden detection, likely increasing false positives. Option C is wrong because lowering severity does not reduce false positives. Option D is wrong because increasing time range does not help.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Add an additional filter to exclude PowerShell executions from specific administrative user accounts
Why this is correct
Excluding known admin accounts helps reduce noise while keeping detection for other users.
- ✗
Increase the query time range to 30 days
Why it's wrong here
Time range does not affect false positives in this context.
- ✗
Change the severity to Informational to suppress alerts
Why it's wrong here
Severity change does not reduce false positives; it only changes alert classification.
- ✗
Remove the parent process filter and rely only on FileName == 'powershell.exe'
Why it's wrong here
This would increase false positives by detecting all PowerShell launches.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.