SC-200 Respond to security incidents Practice Question
Exhibit
Refer to the exhibit.
```powershell
# Microsoft Defender XDR Advanced Hunting query
DeviceProcessEvents
| where Timestamp > ago(7d)
| where ProcessCommandLine has_any ("powershell", "cmd", "wscript")
| where FileName has_any ("rundll32.exe", "regsvr32.exe", "mshta.exe")
| project Timestamp, DeviceName, ProcessCommandLine
```Refer to the exhibit. A SOC analyst runs this Advanced Hunting query in Microsoft Defender XDR to detect potential living-off-the-land (LotL) attacks. An alert is triggered when a device shows multiple occurrences of 'mshta.exe' executing with a remote script. Which additional data source should the analyst check to confirm the attack?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DeviceNetworkEvents
DeviceNetworkEvents would show network connections made by mshta.exe to remote hosts, confirming the LotL attack. The other options are not directly relevant or are redundant.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
DeviceFileEvents
Why it's wrong here
DeviceFileEvents records file creation, modification and deletion, so it shows dropped payloads but not the network connections mshta.exe made to fetch the remote script. It is tempting because file telemetry often reveals malware artefacts, and would be correct when investigating dropped files or ransomware encryption activity.
- ✓
DeviceNetworkEvents
Why this is correct
DeviceNetworkEvents supplies the outbound connection telemetry — remote IP, port, and URL — that mshta.exe generated when fetching the remote script. This directly confirms the LotL attack by correlating the process execution already surfaced in the hunting query with the actual command-and-control or payload download destination, satisfying the requirement to verify external network contact.
- ✗
DeviceLogonEvents
Why it's wrong here
DeviceLogonEvents captures authentication activity, so it cannot confirm the outbound network connection mshta.exe established to retrieve the remote script. It is tempting because logon data exposes credential abuse, and would be correct when investigating brute-force, pass-the-hash or anomalous sign-in activity.
- ✗
DeviceRegistryEvents
Why it's wrong here
DeviceRegistryEvents records registry key creation and modification, so it cannot confirm remote script retrieval or execution by mshta.exe. Analysts are tempted because registry persistence is a common LotL technique, and this table would be correct when investigating autorun or Run-key abuse rather than network-fetched script execution.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.