Courseiva

SC-200 Manage a security operations environment Practice Question

You are a security operations analyst for a company that uses Microsoft Defender XDR. You need to configure a custom detection rule that will trigger an alert when a specific process is executed on any device. The process name is 'malicious.exe'. You want the alert to be generated only when the process is executed with a command line containing '--encrypt'. Which query language should you use to define the custom detection rule?

⚠ Common exam trap

Watch out — candidates often confuse the query languages used by different Microsoft security products; Defender XDR custom detections use KQL, not SQL or PowerShell.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Kusto Query Language (KQL) against the DeviceProcessEvents table.

Custom detection rules in Microsoft Defender XDR are created by writing KQL queries against advanced hunting tables. For process execution events, the DeviceProcessEvents table is appropriate. By filtering on the process file name and command line, you can precisely trigger alerts for the specified condition.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Kusto Query Language (KQL) against the DeviceProcessEvents table.

    Why this is correct

    Custom detection rules in Microsoft Defender XDR use KQL to query advanced hunting tables. The DeviceProcessEvents table contains process creation events, including process name and command line. Using KQL, you can filter for FileName == 'malicious.exe' and ProcessCommandLine contains '--encrypt' to trigger the alert as required.

  • ✗

    SQL against the SecurityEvent table in Microsoft Sentinel.

    Why it's wrong here

    Microsoft Defender XDR custom detections do not use SQL, and the SecurityEvent table is in Microsoft Sentinel, not Defender XDR. While Sentinel can query Defender XDR data, custom detections in Defender XDR are built with KQL against advanced hunting tables like DeviceProcessEvents, not SQL.

  • ✗

    PowerShell script that queries the Windows Event Log for process creation events.

    Why it's wrong here

    Custom detection rules in Microsoft Defender XDR are not based on PowerShell scripts. They are defined using KQL queries within the Defender portal. A PowerShell script would require a scheduled task or automation, which is not how native custom detections work and would not integrate directly with Defender XDR alerting.

  • ✗

    Azure Resource Graph query against the Microsoft Defender for Endpoint resources.

    Why it's wrong here

    Azure Resource Graph is for querying Azure resources, not for endpoint process events. It cannot access DeviceProcessEvents or other Defender for Endpoint advanced hunting tables. This approach is unrelated to creating custom detections in Defender XDR.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.