SC-200 Perform threat hunting Practice Question
To hunt for malicious PowerShell encoded commands, which columns in the DeviceProcessEvents table in Microsoft 365 Defender advanced hunting should you focus on?
⚠ Common exam trap
SC-200 often tests whether candidates know which column holds the actual command-line arguments — candidates pick FileName or InitiatingProcessFileName because they sound process-related, missing that ProcessCommandLine is where encoded payloads live.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ProcessCommandLine
Encoded PowerShell commands (e.g., -EncodedCommand or -enc) appear in the full command line used to launch the process, which is captured in the ProcessCommandLine column of DeviceProcessEvents. Filtering or searching ProcessCommandLine for base64-like strings or the -enc switch is the standard hunting technique for detecting obfuscated PowerShell execution.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
DeviceName
Why it's wrong here
DeviceName is a host identifier that tells you which machine the process ran on, but it contains zero information about the PowerShell invocation itself. Encoded command strings are passed as arguments to powershell.exe, so without inspecting the actual command line you cannot detect a base64 payload. Use DeviceName only to scope a hunt to specific endpoints, not to identify malicious encoding.
- ✗
FileName
Why it's wrong here
FileName captures only the executable image, such as powershell.exe or pwsh.exe, and not the arguments passed to it. Malicious encoded commands are supplied via the -EncodedCommand parameter in the argument list, so this column will simply show a benign-looking PowerShell process. Filtering on FileName alone yields false positives because PowerShell is a legitimate, commonly used binary.
- ✓
ProcessCommandLine
Why this is correct
ProcessCommandLine contains the full command line, including the -EncodedCommand parameter and the base64 string attackers use to hide their payload. This is the primary field to inspect when hunting for obfuscated PowerShell, as the encoded blob is present verbatim. In Microsoft 365 Defender's DeviceProcessEvents, this field enables decoding and further analysis, making it the directly relevant column.
- ✗
InitiatingProcessFileName
Why it's wrong here
InitiatingProcessFileName identifies the parent executable that launched PowerShell (e.g., WINWORD.EXE or mshta.exe), which is valuable for attack-chain reconstruction but does not expose the encoded command itself. While an unusual parent can be a useful lead, the actual base64 payload lives in the child's ProcessCommandLine. This column is a secondary evidence source, not the hunting field for encoded content.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.