Courseiva
Perform threat hunting →mediumMultiple Choice

SC-200 Perform threat hunting Practice Question

Exhibit

Refer to the exhibit.

```kusto
// KQL query in Microsoft Sentinel
DeviceProcessEvents
| where Timestamp > ago(7d)
| where FileName == "cmd.exe"
| where ProcessCommandLine contains "powershell"
| project Timestamp, DeviceName, AccountName, ProcessCommandLine
| join kind=inner (
    DeviceNetworkEvents
    | where Timestamp > ago(7d)
    | where RemotePort == 443
) on DeviceName
```

Refer to the exhibit. The KQL query is used for threat hunting. What is the primary purpose of this query?

⚠ Common exam trap

SC-200 often tests whether candidates read the *join and filter* conditions rather than the surface process names — distractors like 'download files' or 'lateral movement' sound plausible but are not what the query's columns and port filter actually select for.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Identify devices where cmd.exe launched PowerShell and made outbound HTTPS connections.

The KQL query joins process creation events where `cmd.exe` is the parent and `powershell.exe` is the child with network events from the same device, filtering for outbound HTTPS (port 443) — this pattern identifies devices where a command shell spawned PowerShell that then made encrypted outbound connections, a common living-off-the-land technique. The join on DeviceId and time window is what ties the process chain to the network activity, which is the query's defining purpose.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Identify devices where cmd.exe launched PowerShell and made outbound HTTPS connections.

    Why this is correct

    The query correlates DeviceProcessEvents with DeviceNetworkEvents, joining on DeviceId and a time window to link cmd.exe spawning PowerShell with subsequent outbound HTTPS traffic. This satisfies the hunting objective of surfacing suspicious process-to-network chains, where a command shell launching PowerShell and beaconing externally indicates potential malicious activity.

  • ✗

    Find devices where PowerShell was used to download files.

    Why it's wrong here

    PowerShell download activity is only one execution vector, so this query cannot isolate devices by that criterion alone; it correlates broader process and network events across the environment. It tempts because hunting for script-based download behaviour is a legitimate technique when investigating fileless malware or living-off-the-land intrusions.

  • ✗

    Detect lateral movement using remote services.

    Why it's wrong here

    Remote service logons appear in SecurityEvent as type 3 or 10, not the queried event IDs, so this query cannot surface them. It tempts because lateral movement via SMB, WMI or PsExec is a genuine hunting goal, and such queries would be right when correlating logon types with process creation on target hosts.

  • ✗

    Identify cmd.exe running with high integrity.

    Why it's wrong here

    The query does not check integrity levels.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.