SC-200 Perform threat hunting Practice Question
While threat hunting, you find a suspicious scheduled task that runs a PowerShell script from a temp directory. You want to check if this task exists on other devices in the environment. Which Microsoft Defender for Endpoint advanced hunting table would you query?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DeviceEvents
The `DeviceEvents` table includes scheduled task creation events (ActionType: ScheduledTaskCreated). Option A is wrong because `DeviceProcessEvents` focuses on process execution, not task creation. Option B is wrong because `DeviceNetworkEvents` is for network connections. Option D is wrong because `DeviceRegistryEvents` is for registry changes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
DeviceProcessEvents
Why it's wrong here
DeviceProcessEvents records process creation, including PowerShell executions, but not the scheduled task definitions that launch them, so it cannot enumerate the task across devices. It is tempting because the script runs as a process, yet DeviceEvents is the table holding scheduled task creation and registration data.
- ✗
DeviceNetworkEvents
Why it's wrong here
DeviceNetworkEvents captures connection metadata such as remote IPs and ports, containing no scheduled task definitions or their actions. It is tempting because a malicious task may initiate network traffic, but querying it cannot confirm whether the task itself exists on other devices; DeviceEvents holds that task data.
- ✓
DeviceEvents
Why this is correct
DeviceEvents records scheduled task creation and related process activity, including the task's action and initiating command line. Querying it surfaces matching PowerShell-from-temp-directory tasks across enrolled devices, letting you determine whether the suspicious task exists elsewhere in the estate.
- ✗
DeviceRegistryEvents
Why it's wrong here
DeviceRegistryEvents records registry key and value modifications, not scheduled task creation, which Windows stores in task files rather than the registry. It is tempting because tasks have registry-adjacent artefacts, but DeviceEvents is the table that surfaces scheduled task registration and related activity across devices.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.