SC-200 Manage a security operations environment Practice Question
You are a security operations analyst for a company that uses Microsoft Defender XDR. You need to configure a custom detection rule that will trigger an alert when a specific process is executed on any device. The process name is 'malicious.exe'. You want the alert to be generated only when the process is executed with a command line containing '--encrypt'. Which query language should you use to define the custom detection rule?
⚠ Common exam trap
Watch out — candidates often confuse the query languages used by different Microsoft security products; Defender XDR custom detections use KQL, not SQL or PowerShell.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Kusto Query Language (KQL) against the DeviceProcessEvents table.
Custom detection rules in Microsoft Defender XDR are created by writing KQL queries against advanced hunting tables. For process execution events, the DeviceProcessEvents table is appropriate. By filtering on the process file name and command line, you can precisely trigger alerts for the specified condition.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Kusto Query Language (KQL) against the DeviceProcessEvents table.
Why this is correct
Custom detection rules in Microsoft Defender XDR use KQL to query advanced hunting tables. The DeviceProcessEvents table contains process creation events, including process name and command line. Using KQL, you can filter for FileName == 'malicious.exe' and ProcessCommandLine contains '--encrypt' to trigger the alert as required.
- ✗
SQL against the SecurityEvent table in Microsoft Sentinel.
Why it's wrong here
Microsoft Defender XDR custom detections do not use SQL, and the SecurityEvent table is in Microsoft Sentinel, not Defender XDR. While Sentinel can query Defender XDR data, custom detections in Defender XDR are built with KQL against advanced hunting tables like DeviceProcessEvents, not SQL.
- ✗
PowerShell script that queries the Windows Event Log for process creation events.
Why it's wrong here
Custom detection rules in Microsoft Defender XDR are not based on PowerShell scripts. They are defined using KQL queries within the Defender portal. A PowerShell script would require a scheduled task or automation, which is not how native custom detections work and would not integrate directly with Defender XDR alerting.
- ✗
Azure Resource Graph query against the Microsoft Defender for Endpoint resources.
Why it's wrong here
Azure Resource Graph is for querying Azure resources, not for endpoint process events. It cannot access DeviceProcessEvents or other Defender for Endpoint advanced hunting tables. This approach is unrelated to creating custom detections in Defender XDR.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.