Courseiva

SC-200 Respond to security incidents Practice Question

Exhibit

Refer to the exhibit.

```kusto
DeviceProcessEvents
| where Timestamp > ago(1h)
| where FileName == "powershell.exe"
| where ProcessCommandLine contains "-EncodedCommand"
| project Timestamp, DeviceName, ProcessCommandLine
```

Refer to the exhibit. You run this KQL query in Microsoft Defender XDR to detect suspicious PowerShell activity. Why might this query generate many false positives?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Legitimate administrators often use encoded PowerShell commands.

Legitimate administrators often use encoded PowerShell commands, which would match this query and generate false positives. Option A is wrong because the time range shown in the exhibit (e.g., 7 days) is not excessively broad for hunting. Option B is wrong because the query is specific to encoded commands, but it does not miss attacks; it targets a specific technique. Option D is wrong because, while filtering by user could reduce noise, the main reason for false positives is that encoded commands are used legitimately, not because of the absence of user filtering.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The time range is too broad.

    Why it's wrong here

    A broad time range widens the search window but does not itself create false positives; the query's filter logic determines which events match. Time-range tuning belongs to scheduled analytics rules, where narrowing the lookback reduces repeated alerting on stale events. Here the false positives stem from the query matching legitimate PowerShell usage, not from how far back it searches.

  • ✗

    The query is too specific and misses many attacks.

    Why it's wrong here

    The query's false positives stem from its broad matching logic, not its specificity, so this option misidentifies the failure mode. It is tempting because narrow, over-filtered queries genuinely miss attacks, and tightening detection scope is a real tuning concern. That scenario applies when a query returns too few results, not excessive noise.

  • ✓

    Legitimate administrators often use encoded PowerShell commands.

    Why this is correct

    Encoded PowerShell is a legitimate administrative technique, so a detection rule flagging encoded commands matches benign activity and inflates false positives. The query's logic keys on encoding itself, which is not inherently malicious, satisfying the stem's constraint that the rule triggers on common legitimate behaviour.

  • ✗

    The query does not filter by user.

    Why it's wrong here

    Omitting a user filter broadens results to every account, so benign administrative or service-account PowerShell triggers alerts. The query's real weakness is its detection logic, not user scoping. Filtering by user narrows noise but does not address the underlying pattern.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.