SC-200 Respond to security incidents Practice Question
Exhibit
Refer to the exhibit. ```kusto DeviceProcessEvents | where Timestamp > ago(1h) | where FileName == "powershell.exe" | where ProcessCommandLine contains "-EncodedCommand" | project Timestamp, DeviceName, ProcessCommandLine ```
Refer to the exhibit. You run this KQL query in Microsoft Defender XDR to detect suspicious PowerShell activity. Why might this query generate many false positives?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Legitimate administrators often use encoded PowerShell commands.
Legitimate administrators often use encoded PowerShell commands, which would match this query and generate false positives. Option A is wrong because the time range shown in the exhibit (e.g., 7 days) is not excessively broad for hunting. Option B is wrong because the query is specific to encoded commands, but it does not miss attacks; it targets a specific technique. Option D is wrong because, while filtering by user could reduce noise, the main reason for false positives is that encoded commands are used legitimately, not because of the absence of user filtering.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The time range is too broad.
Why it's wrong here
A broad time range widens the search window but does not itself create false positives; the query's filter logic determines which events match. Time-range tuning belongs to scheduled analytics rules, where narrowing the lookback reduces repeated alerting on stale events. Here the false positives stem from the query matching legitimate PowerShell usage, not from how far back it searches.
- ✗
The query is too specific and misses many attacks.
Why it's wrong here
The query's false positives stem from its broad matching logic, not its specificity, so this option misidentifies the failure mode. It is tempting because narrow, over-filtered queries genuinely miss attacks, and tightening detection scope is a real tuning concern. That scenario applies when a query returns too few results, not excessive noise.
- ✓
Legitimate administrators often use encoded PowerShell commands.
Why this is correct
Encoded PowerShell is a legitimate administrative technique, so a detection rule flagging encoded commands matches benign activity and inflates false positives. The query's logic keys on encoding itself, which is not inherently malicious, satisfying the stem's constraint that the rule triggers on common legitimate behaviour.
- ✗
The query does not filter by user.
Why it's wrong here
Omitting a user filter broadens results to every account, so benign administrative or service-account PowerShell triggers alerts. The query's real weakness is its detection logic, not user scoping. Filtering by user narrows noise but does not address the underlying pattern.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.