SC-200 Perform threat hunting Practice Question
You are a threat hunter in Microsoft Sentinel. You suspect an attacker is using the Windows utility certutil.exe to download malicious payloads from an external URL. You want to write a hunting query that detects command lines where certutil.exe is used with the -urlcache or -verifyctl arguments. Which KQL query should you use?
⚠ Common exam trap
The trap here is assuming that network or file events will reveal command-line arguments, when only process creation events capture the full command line used to launch a binary.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DeviceProcessEvents | where FileName == "certutil.exe" | where ProcessCommandLine has_any ("-urlcache", "-verifyctl")
The correct query uses DeviceProcessEvents to capture process creation events and filters for certutil.exe with the suspicious arguments -urlcache or -verifyctl. This directly matches the hunting hypothesis. Other tables either lack command-line data or use incorrect fields. DeviceProcessEvents is the authoritative source for process command lines in Microsoft Defender XDR, making it the right choice for detecting this living-off-the-land binary abuse.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
DeviceNetworkEvents | where InitiatingProcessFileName == "certutil.exe" | where RemoteUrl contains "http"
Why it's wrong here
DeviceNetworkEvents records network connections and may include URLs, but it does not capture the command-line arguments used to launch certutil.exe. The scenario requires detecting the specific arguments -urlcache or -verifyctl, which are only visible in process creation events. Filtering on RemoteUrl would miss cases where the download URL is not directly logged or where certutil uses other protocols. This table is not the right source for command-line based hunting.
- ✗
DeviceEvents | where ActionType == "CertUtilDownload" | where AdditionalFields contains "urlcache"
Why it's wrong here
DeviceEvents contains various event types, but there is no ActionType named CertUtilDownload. ActionType values are predefined and do not include specific command-line arguments. The AdditionalFields column may hold extra data, but it is not guaranteed to contain command-line details for certutil. This query relies on a non-existent action type and would return no results, missing the threat entirely.
- ✗
DeviceFileEvents | where FileName == "certutil.exe" | where FolderPath contains "urlcache"
Why it's wrong here
DeviceFileEvents tracks file creation, modification, and deletion events, not process execution. The FolderPath of certutil.exe is typically System32 and does not contain the argument string. This query would not detect the use of -urlcache or -verifyctl because those are command-line parameters, not file paths. Therefore, it fails to identify the malicious behavior described.
- ✓
DeviceProcessEvents | where FileName == "certutil.exe" | where ProcessCommandLine has_any ("-urlcache", "-verifyctl")
Why this is correct
This query correctly targets the DeviceProcessEvents table in Microsoft Defender XDR advanced hunting, filters for the process name certutil.exe, and uses has_any to match either of the suspicious arguments. Because DeviceProcessEvents captures process creation events with full command lines, it is the appropriate table for detecting this behavior. The has_any operator efficiently checks for multiple substrings in the command line, making it ideal for this scenario.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.