Courseiva
Perform threat hunting →hardMultiple Choice

SC-200 Perform threat hunting Practice Question

You are a threat hunter at Fabrikam. You suspect that an attacker is using the Win32_Process class to create a process on a remote workstation via WMI. You need to write an advanced hunting query in Microsoft Defender XDR to detect this activity. Which table should you query to find WMI process creation events?

⚠ Common exam trap

The trap here is assuming that all process creation events are in DeviceProcessEvents, but WMI-specific process creation is logged in DeviceEvents with a distinct ActionType.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

DeviceEvents

To detect WMI process creation, you need to query a table that specifically logs WMI activity. In Microsoft Defender XDR advanced hunting, the DeviceEvents table includes an ActionType called WmiProcessCreate that captures process creation via WMI, including the remote caller and command line. Filtering DeviceEvents for this ActionType will surface the relevant events.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    DeviceProcessEvents

    Why it's wrong here

    DeviceProcessEvents contains standard process creation events from endpoint telemetry, such as those captured by Sysmon or Windows Event ID 4688. While it can show process creations, it does not specifically capture WMI-related process creation events that include the WMI provider host details or the remote caller information needed to detect this specific technique.

  • ✓

    DeviceEvents

    Why this is correct

    DeviceEvents includes various event types, such as WmiProcessCreate, which specifically logs process creation via WMI. This table captures the WMI provider host process, the command line, and the remote caller, allowing you to detect remote WMI process creation. Querying DeviceEvents for ActionType == 'WmiProcessCreate' is the correct approach for this scenario.

  • ✗

    DeviceNetworkEvents

    Why it's wrong here

    DeviceNetworkEvents records network connection events, such as TCP connections and DNS queries. It does not contain process creation details. While WMI remote process creation involves network activity, the specific event of process creation is not captured in this table. You need a table that logs the process creation action itself.

  • ✗

    DeviceRegistryEvents

    Why it's wrong here

    DeviceRegistryEvents logs registry key modifications, which can be useful for detecting persistence or configuration changes. However, it does not record process creation events. WMI process creation does not directly modify the registry in a way that would be captured here, so this table is not suitable for detecting the described activity.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.