SC-200 Perform threat hunting Practice Question
You are a threat hunter at Fabrikam. You suspect that an attacker is using the Win32_Process class to create a process on a remote workstation via WMI. You need to write an advanced hunting query in Microsoft Defender XDR to detect this activity. Which table should you query to find WMI process creation events?
⚠ Common exam trap
The trap here is assuming that all process creation events are in DeviceProcessEvents, but WMI-specific process creation is logged in DeviceEvents with a distinct ActionType.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DeviceEvents
To detect WMI process creation, you need to query a table that specifically logs WMI activity. In Microsoft Defender XDR advanced hunting, the DeviceEvents table includes an ActionType called WmiProcessCreate that captures process creation via WMI, including the remote caller and command line. Filtering DeviceEvents for this ActionType will surface the relevant events.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
DeviceProcessEvents
Why it's wrong here
DeviceProcessEvents contains standard process creation events from endpoint telemetry, such as those captured by Sysmon or Windows Event ID 4688. While it can show process creations, it does not specifically capture WMI-related process creation events that include the WMI provider host details or the remote caller information needed to detect this specific technique.
- ✓
DeviceEvents
Why this is correct
DeviceEvents includes various event types, such as WmiProcessCreate, which specifically logs process creation via WMI. This table captures the WMI provider host process, the command line, and the remote caller, allowing you to detect remote WMI process creation. Querying DeviceEvents for ActionType == 'WmiProcessCreate' is the correct approach for this scenario.
- ✗
DeviceNetworkEvents
Why it's wrong here
DeviceNetworkEvents records network connection events, such as TCP connections and DNS queries. It does not contain process creation details. While WMI remote process creation involves network activity, the specific event of process creation is not captured in this table. You need a table that logs the process creation action itself.
- ✗
DeviceRegistryEvents
Why it's wrong here
DeviceRegistryEvents logs registry key modifications, which can be useful for detecting persistence or configuration changes. However, it does not record process creation events. WMI process creation does not directly modify the registry in a way that would be captured here, so this table is not suitable for detecting the described activity.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.