SC-200 Respond to security incidents Practice Question
Exhibit
Refer to the exhibit. ``` $huntQuery = @" DeviceProcessEvents | where Timestamp > ago(7d) | where FileName == "powershell.exe" | where ProcessCommandLine contains "-EncodedCommand" | project Timestamp, DeviceName, AccountName, ProcessCommandLine | take 1000 "@ $result = Invoke-AzOperationalInsightsQuery -WorkspaceId "..." -Query $huntQuery ```
Refer to the exhibit. A security analyst runs this PowerShell script to query a Log Analytics workspace. What is the purpose of this query?
⚠ Common exam trap
The SC-200 exam often tests the ability to recognize that the `-enc` parameter is a shorthand for `-EncodedCommand`, which is a key indicator of obfuscated PowerShell execution, and candidates may mistakenly think the query simply lists all PowerShell executions (option B) without noticing the specific filter.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Detect suspicious PowerShell activity using encoded commands
The PowerShell script uses the `| where {$_ -match 'powershell.*-enc'} ` filter to search for command lines containing 'powershell' followed by '-enc', which is the alias for the `-EncodedCommand` parameter. This parameter is commonly used by attackers to obfuscate malicious PowerShell commands by passing them as a Base64-encoded string. The query is specifically designed to detect suspicious PowerShell executions that use encoded commands, making option D correct.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Count the number of unique devices
Why it's wrong here
The query has no aggregation operators (such as summarize, dcount, or count) to calculate the number of unique devices. It returns individual event rows that match the command-line pattern, so multiple events from the same device would appear separately, not as a distinct count. A unique-device count would require a separate projection and deduplication step that is absent from the query.
- ✗
Identify all PowerShell executions in the last 7 days
Why it's wrong here
The query is specifically scoped to command lines that include '-EncodedCommand', not to all PowerShell executions. Standard PowerShell invocations without that parameter would be ignored, and the query may not even have a time range filter of 7 days. To identify all PowerShell executions, you would need to filter on the Image or ProcessName field with no command-line obfuscation filter.
- ✗
List all processes run by a specific account
Why it's wrong here
The query applies no filter on the Account, User, or InitiatingProcessAccount fields, so it cannot identify processes run by a specific account. It focuses solely on the presence of the encoded command switch in the command line, which could relate to any account on any device. Listing processes for a particular account would require an equality condition on the account identifier.
- ✓
Detect suspicious PowerShell activity using encoded commands
Why this is correct
The query explicitly examines command-line arguments for the '-EncodedCommand' parameter, which is a well-known PowerShell feature that attackers abuse to obfuscate malicious scripts. When an encoded command is present, the actual script is a Base64-encoded string, making static detection more difficult and justifying a suspicion review. Security analysts use such queries in advanced hunting to surface potentially hidden or obfuscated PowerShell activity.
- ✗
Find devices that have not run PowerShell recently
Why it's wrong here
The query searches for events where PowerShell did execute with an encoded command, not for devices that are absent from those events. To find devices that have not run PowerShell recently, you would need to compare the full device inventory against the set of devices found in PowerShell execution events, often using a left anti join or a 'where not in' clause. The query as written only returns devices with the specified activity.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.