SC-200 Respond to security incidents Practice Question
Exhibit
Refer to the exhibit.
```
{
"type": "Microsoft.SecurityInsights/alertRules",
"apiVersion": "2022-01-01-preview",
"name": "Suspicious Process Creation",
"properties": {
"displayName": "Suspicious Process Creation",
"description": "Detects suspicious process creation events.",
"severity": "High",
"query": "SecurityEvent | where EventID == 4688 | where ProcessName endswith '\\cmd.exe' | where ParentProcessName endswith '\\winword.exe'",
"queryFrequency": "PT5H",
"queryPeriod": "PT5H",
"triggerOperator": "GreaterThan",
"triggerThreshold": 0
}
}Refer to the exhibit. You are deploying this analytics rule in Microsoft Sentinel. Which activity will trigger an alert?
⚠ Common exam trap
Many candidates confuse the parent-child process direction, assuming any execution of cmd.exe or winword.exe will trigger the alert, but the rule explicitly requires winword.exe as the parent and cmd.exe as the child, not the reverse.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Word launching cmd.exe
The analytics rule is configured to trigger an alert when a process creation event (Event ID 4688) has a parent process of 'winword.exe' and a child process of 'cmd.exe'. This specific parent-child relationship indicates that Microsoft Word is launching a command prompt, which is a common technique used in malicious documents to execute commands. The rule's query filters for 'ParentImage' containing 'winword.exe' and 'Image' containing 'cmd.exe', so only when Word launches cmd.exe will the alert fire.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
cmd.exe launching winword.exe
Why it's wrong here
The query condition has process name winword.exe and command line contains cmd.exe, meaning the parent process is winword.exe and the child process is cmd.exe. This option reverses the direction, describing cmd.exe as the parent creating winword.exe, which would not match the rule's filter that requires the parent to be Microsoft Word. Such a chain would indicate a command shell spawning a document editor, a different and less common attack pattern than macro-based Office process launching a shell.
- ✗
Any process creation event
Why it's wrong here
The analytics rule does not alert on every process creation; it uses two conditions: ParentImage equals 'winword.exe' and CommandLine contains 'cmd.exe'. A generic process creation rule would generate excessive noise and miss the specificity of the suspicious parent-child relationship. This option ignores the predicate that constrains both the parent process and the child process command line, so it does not match the rule's logic.
- ✗
Winword.exe execution
Why it's wrong here
Merely observing winword.exe running is insufficient because the rule requires the command line of a child process to contain 'cmd.exe'. The rule's query joins process creation events where the parent image is the Word executable and the child process's command line includes cmd.exe, meaning Word execution alone won't satisfy the conditions. Without the child shell process, there is no indication of the macro-level command execution that the rule is designed to detect.
- ✗
Any cmd.exe execution
Why it's wrong here
The rule only matches cmd.exe instances that are directly spawned by winword.exe, as indicated by the ParentImage equals 'winword.exe' condition. A standalone cmd.exe launch—whether by the user, Task Scheduler, or another process—will not match because the parent process is not Word. Thus, this option is too broad and fails to capture the specific Office-parented command shell that the query targets.
- ✓
Word launching cmd.exe
Why this is correct
The query conditions—ParentImage equals 'winword.exe' and CommandLine contains 'cmd.exe'—precisely describe a Microsoft Word process creating a child command prompt. This is a classic indicator of a document with an embedded macro executing a shell command, a common technique for lateral movement or payload delivery. Therefore, this option correctly interprets the rule's intent and logic.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.