SC-200 Perform threat hunting Practice Question
Exhibit
Refer to the exhibit. ```kusto DeviceProcessEvents | where Timestamp > ago(7d) | where InitiatingProcessFileName == "powershell.exe" | where FileName == "rundll32.exe" | where ProcessCommandLine contains "javascript:" | project Timestamp, DeviceName, AccountName, FileName, ProcessCommandLine ```
The KQL query above is used in a threat hunt. What is the most likely scenario this query is designed to detect?
⚠ Common exam trap
SC-200 often tests the ability to distinguish between different LOLBin techniques, such as confusing rundll32.exe with regsvr32.exe or misidentifying the specific script type being executed.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Hunting for code execution via rundll32.exe loading JavaScript
The query specifically looks for rundll32.exe loading JavaScript files, which is a known technique for executing malicious code while evading detection. This aligns with option C, as it directly describes the behavior the query is designed to hunt for. The query likely includes process creation events where rundll32.exe is the parent or child process and the command line contains .js or .jse extensions, indicating JavaScript execution.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Identification of lateral movement using PsExec
Why it's wrong here
The query appears to focus on process creation events, specifically looking for a PowerShell process spawning rundll32.exe with a command line containing 'javascript:'. PsExec-based lateral movement typically leaves traces such as service creation (Service Control Manager events) and network connections to admin shares, none of which are referenced here. Additionally, there is no presence of PsExec's executable name or associated remote execution indicators in the query, making this explanation incorrect.
- ✗
Discovery of data exfiltration using FTP
Why it's wrong here
Data exfiltration via FTP usually involves outbound network connections to port 21, FTP client processes, or file upload activity, none of which appear in this KQL query. The query filters on process execution with a specific 'javascript:' argument in rundll32.exe, which has no correlation with FTP protocol indicators. Therefore, this hunt is not designed to discover FTP-based exfiltration, as it lacks the necessary network-level or FTP-specific artifacts.
- ✓
Hunting for code execution via rundll32.exe loading JavaScript
Why this is correct
This query is correctly hunting for a known LOLBin technique where an attacker uses rundll32.exe to execute JavaScript code by placing 'javascript:' in the command line. When PowerShell (or another process) launches rundll32 with that argument, it triggers the JScript engine to evaluate the supplied script, allowing arbitrary code execution while masquerading as a legitimate Windows binary. This pattern is documented in MITRE ATT&CK as Signed Binary Proxy Execution (T1218.011), and the combination of the parent-child process relationship and the 'javascript:' string makes it a strong hunting indicator.
- ✗
Detection of regsvr32.exe being used to execute scriptlet files
Why it's wrong here
Regsvr32.exe scriptlet execution is an alternative technique that involves using regsvr32 to run .sct files via scrobj.dll, often bypassing application whitelisting. However, the query explicitly filters for rundll32.exe as the process, not regsvr32.exe, so it would not capture those specific events. Even the command-line substring 'javascript:' is not a typical indicator for regsvr32 scriptlet abuse, which usually references remote .sct URLs. Hence, this option misidentifies the binary and the attack pattern.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.