SC-200 Perform threat hunting Practice Question
You are a threat hunter for a company that uses Microsoft Defender for Endpoint (now part of Microsoft Defender XDR). You need to investigate a potential privilege escalation attack. You have collected process creation events from endpoints and want to identify instances where a process with low integrity level spawned a process with high integrity level. The DeviceProcessEvents table includes fields: DeviceName, AccountName, InitiatingProcessFileName, InitiatingProcessIntegrityLevel, ProcessFileName, ProcessIntegrityLevel. You need to write an advanced hunting query that returns the top 10 devices where this escalation occurred most frequently in the last 7 days. Which query should you use?
⚠ Common exam trap
SC-200 often tests whether candidates confuse integrity-level escalation (Low to High) with any integrity-level change or with user privilege elevation, causing them to pick the != or Medium-to-High filter.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DeviceProcessEvents | where Timestamp > ago(7d) | where InitiatingProcessIntegrityLevel == "Low" and ProcessIntegrityLevel == "High" | summarize count() by DeviceName | top 10 by count_
The query must filter for a genuine privilege escalation, which in Windows integrity-level terms means a low-integrity process spawning a high-integrity process. Option A correctly compares InitiatingProcessIntegrityLevel == "Low" against ProcessIntegrityLevel == "High", then aggregates by DeviceName and uses top 10 by count_ to surface the devices with the most escalation events in the last 7 days. This matches the stated requirement exactly.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
DeviceProcessEvents | where Timestamp > ago(7d) | where InitiatingProcessIntegrityLevel == "Low" and ProcessIntegrityLevel == "High" | summarize count() by DeviceName | top 10 by count_
Why this is correct
Filtering on InitiatingProcessIntegrityLevel "Low" and ProcessIntegrityLevel "High" isolates genuine low-to-high integrity transitions, the exact escalation pattern sought. Summarising count() by DeviceName then top 10 by count_ ranks the noisiest endpoints over the ago(7d) window, matching both the frequency and timeframe constraints.
- ✗
DeviceProcessEvents | where Timestamp > ago(7d) | where InitiatingProcessIntegrityLevel == "Medium" and ProcessIntegrityLevel == "High" | summarize count() by DeviceName | top 10 by count_
Why it's wrong here
Hard-coding "Medium" and "High" misses low-to-high escalation from other integrity levels, such as Low spawning High. It is tempting because Medium-to-High is the common desktop pattern, and it would be correct if the requirement named those two specific integrity levels.
- ✗
DeviceProcessEvents | where Timestamp > ago(7d) | where InitiatingProcessIntegrityLevel != ProcessIntegrityLevel | summarize count() by DeviceName | top 10 by count_
Why it's wrong here
Includes all mismatches, not just low to high.
- ✗
DeviceProcessEvents | where Timestamp > ago(7d) | where InitiatingProcessFileName != ProcessFileName | summarize count() by DeviceName | top 10 by count_
Why it's wrong here
Filtering on differing filenames ignores integrity levels entirely, so privilege escalation is never detected; the query merely counts processes whose names differ. It is tempting because summarising by DeviceName with top 10 matches the requested output shape, and filename comparison is a common hunting heuristic for suspicious parent-child pairs.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SC-200
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which THREE techniques are commonly used in threat hunting within Microsoft Defender XDR to detect privilege escalation?
hard- A.Spearphishing attachment
- B.Data exfiltration
- ✓ C.Token manipulation
- ✓ D.Access token manipulation
- ✓ E.Process injection
Why C: Token manipulation (C) is a core privilege-escalation technique in Windows, where an attacker duplicates, impersonates, or steals a primary or impersonation token (e.g., via DuplicateTokenEx or ImpersonateLoggedOnUser) to run code under a higher-integrity or more privileged account, making it a key hunting signal in Microsoft Defender XDR. Access token manipulation (D) is the related MITRE ATT&CK sub-technique (T1134.001) covering theft or forgery of access tokens, including SeDebugPrivilege abuse and token impersonation, which Defender XDR surfaces through advanced hunting queries over DeviceProcessEvents and related tables. Process injection (E) is also a common privilege-escalation and defense-evasion technique (T1055), where code is injected into a higher-privileged process such as lsass.exe or a SYSTEM-owned service to inherit its token and integrity level, and Defender XDR detects it via behaviors like CreateRemoteThread, WriteProcessMemory, and anomalous cross-process access. Spearphishing attachment (A) is an initial-access technique (T1566.001), not a privilege-escalation method, and data exfiltration (B) is a collection/exfiltration-stage activity (TA0010), so neither belongs in a list of privilege-escalation hunting techniques.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.