SC-200 Perform threat hunting Practice Question
You are a threat hunter at Contoso. You suspect that an attacker is using the 'net user' command to create local accounts on compromised machines. You need to write a KQL query in Microsoft Defender XDR advanced hunting to find all instances of 'net user' being executed. Which operator should you use to search for the command line containing 'net user'?
⚠ Common exam trap
The trap here is using has, which searches for whole terms and would not match the phrase 'net user' because it contains a space and is not a single term.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
contains
To detect the 'net user' command, you need to search for the substring within the command line. The contains operator is designed for this purpose and will match any command line that includes 'net user', regardless of position. Other operators like startswith or endswith are too position-specific and would miss common variations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
has
Why it's wrong here
The has operator is optimized for searching for a whole term within a string, but it requires the term to be a full word. For a phrase like 'net user', which includes a space, has would not match because it looks for individual terms. It is more suitable for single-word searches, not multi-word phrases.
- ✗
startswith
Why it's wrong here
The startswith operator checks if the string begins with the specified prefix. While 'net user' could appear at the beginning of a command line, attackers might use full paths like 'C:\Windows\System32\net.exe user', so startswith would miss those cases. It is too restrictive for this detection.
- ✓
contains
Why this is correct
The contains operator checks for a substring anywhere in the string, so it will match command lines that include 'net user' even if there are additional arguments. This is appropriate for detecting the execution of 'net user' because the command may appear with various parameters. However, be aware that contains is case-insensitive and can be slower than has on large datasets.
- ✗
endswith
Why it's wrong here
The endswith operator checks if the string ends with the specified suffix. The 'net user' command is typically followed by arguments such as a username and password, so it will not be at the end of the command line. Using endswith would fail to detect the command in most real-world executions.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.