Courseiva
Perform threat hunting →hardMultiple Choice

SC-200 Perform threat hunting Practice Question

While threat hunting, you find a suspicious scheduled task that runs a PowerShell script from a temp directory. You want to check if this task exists on other devices in the environment. Which Microsoft Defender for Endpoint advanced hunting table would you query?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

DeviceEvents

The `DeviceEvents` table includes scheduled task creation events (ActionType: ScheduledTaskCreated). Option A is wrong because `DeviceProcessEvents` focuses on process execution, not task creation. Option B is wrong because `DeviceNetworkEvents` is for network connections. Option D is wrong because `DeviceRegistryEvents` is for registry changes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    DeviceProcessEvents

    Why it's wrong here

    DeviceProcessEvents records process creation, including PowerShell executions, but not the scheduled task definitions that launch them, so it cannot enumerate the task across devices. It is tempting because the script runs as a process, yet DeviceEvents is the table holding scheduled task creation and registration data.

  • ✗

    DeviceNetworkEvents

    Why it's wrong here

    DeviceNetworkEvents captures connection metadata such as remote IPs and ports, containing no scheduled task definitions or their actions. It is tempting because a malicious task may initiate network traffic, but querying it cannot confirm whether the task itself exists on other devices; DeviceEvents holds that task data.

  • ✓

    DeviceEvents

    Why this is correct

    DeviceEvents records scheduled task creation and related process activity, including the task's action and initiating command line. Querying it surfaces matching PowerShell-from-temp-directory tasks across enrolled devices, letting you determine whether the suspicious task exists elsewhere in the estate.

  • ✗

    DeviceRegistryEvents

    Why it's wrong here

    DeviceRegistryEvents records registry key and value modifications, not scheduled task creation, which Windows stores in task files rather than the registry. It is tempting because tasks have registry-adjacent artefacts, but DeviceEvents is the table that surfaces scheduled task registration and related activity across devices.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.