Courseiva

SC-200 Respond to security incidents Practice Question

Exhibit

Refer to the exhibit.

```powershell
# Microsoft Defender XDR Advanced Hunting query
DeviceProcessEvents
| where Timestamp > ago(7d)
| where ProcessCommandLine has_any ("powershell", "cmd", "wscript")
| where FileName has_any ("rundll32.exe", "regsvr32.exe", "mshta.exe")
| project Timestamp, DeviceName, ProcessCommandLine
```

Refer to the exhibit. A SOC analyst runs this Advanced Hunting query in Microsoft Defender XDR to detect potential living-off-the-land (LotL) attacks. An alert is triggered when a device shows multiple occurrences of 'mshta.exe' executing with a remote script. Which additional data source should the analyst check to confirm the attack?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

DeviceNetworkEvents

DeviceNetworkEvents would show network connections made by mshta.exe to remote hosts, confirming the LotL attack. The other options are not directly relevant or are redundant.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    DeviceFileEvents

    Why it's wrong here

    DeviceFileEvents records file creation, modification and deletion, so it shows dropped payloads but not the network connections mshta.exe made to fetch the remote script. It is tempting because file telemetry often reveals malware artefacts, and would be correct when investigating dropped files or ransomware encryption activity.

  • ✓

    DeviceNetworkEvents

    Why this is correct

    DeviceNetworkEvents supplies the outbound connection telemetry — remote IP, port, and URL — that mshta.exe generated when fetching the remote script. This directly confirms the LotL attack by correlating the process execution already surfaced in the hunting query with the actual command-and-control or payload download destination, satisfying the requirement to verify external network contact.

  • ✗

    DeviceLogonEvents

    Why it's wrong here

    DeviceLogonEvents captures authentication activity, so it cannot confirm the outbound network connection mshta.exe established to retrieve the remote script. It is tempting because logon data exposes credential abuse, and would be correct when investigating brute-force, pass-the-hash or anomalous sign-in activity.

  • ✗

    DeviceRegistryEvents

    Why it's wrong here

    DeviceRegistryEvents records registry key creation and modification, so it cannot confirm remote script retrieval or execution by mshta.exe. Analysts are tempted because registry persistence is a common LotL technique, and this table would be correct when investigating autorun or Run-key abuse rather than network-fetched script execution.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.