Courseiva
Perform threat hunting →easyMultiple Choice

SC-200 Perform threat hunting Practice Question

To hunt for malicious PowerShell encoded commands, which columns in the DeviceProcessEvents table in Microsoft 365 Defender advanced hunting should you focus on?

⚠ Common exam trap

SC-200 often tests whether candidates know which column holds the actual command-line arguments — candidates pick FileName or InitiatingProcessFileName because they sound process-related, missing that ProcessCommandLine is where encoded payloads live.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

ProcessCommandLine

Encoded PowerShell commands (e.g., -EncodedCommand or -enc) appear in the full command line used to launch the process, which is captured in the ProcessCommandLine column of DeviceProcessEvents. Filtering or searching ProcessCommandLine for base64-like strings or the -enc switch is the standard hunting technique for detecting obfuscated PowerShell execution.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    DeviceName

    Why it's wrong here

    DeviceName is a host identifier that tells you which machine the process ran on, but it contains zero information about the PowerShell invocation itself. Encoded command strings are passed as arguments to powershell.exe, so without inspecting the actual command line you cannot detect a base64 payload. Use DeviceName only to scope a hunt to specific endpoints, not to identify malicious encoding.

  • ✗

    FileName

    Why it's wrong here

    FileName captures only the executable image, such as powershell.exe or pwsh.exe, and not the arguments passed to it. Malicious encoded commands are supplied via the -EncodedCommand parameter in the argument list, so this column will simply show a benign-looking PowerShell process. Filtering on FileName alone yields false positives because PowerShell is a legitimate, commonly used binary.

  • ✓

    ProcessCommandLine

    Why this is correct

    ProcessCommandLine contains the full command line, including the -EncodedCommand parameter and the base64 string attackers use to hide their payload. This is the primary field to inspect when hunting for obfuscated PowerShell, as the encoded blob is present verbatim. In Microsoft 365 Defender's DeviceProcessEvents, this field enables decoding and further analysis, making it the directly relevant column.

  • ✗

    InitiatingProcessFileName

    Why it's wrong here

    InitiatingProcessFileName identifies the parent executable that launched PowerShell (e.g., WINWORD.EXE or mshta.exe), which is valuable for attack-chain reconstruction but does not expose the encoded command itself. While an unusual parent can be a useful lead, the actual base64 payload lives in the child's ProcessCommandLine. This column is a secondary evidence source, not the hunting field for encoded content.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.