SC-200 Perform threat hunting Practice Question
You are hunting for signs of ransomware in your environment using Microsoft 365 Defender. Which advanced hunting table should you primarily query to detect file encryption events?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DeviceFileEvents
DeviceFileEvents captures file creation, modification, and deletion events, which are typical for ransomware encryption. Option A (DeviceNetworkEvents) is wrong because it captures network connections, not file events. Option B (DeviceProcessEvents) is wrong because it captures process creation and termination, not file events. Option D (DeviceRegistryEvents) is wrong because it captures registry modifications, not file events.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
DeviceNetworkEvents
Why it's wrong here
DeviceNetworkEvents captures connection attempts, DNS lookups and listening ports, not local file operations, so encryption activity is invisible. It is tempting because ransomware contacts command-and-control servers, but that network signal is indirect; DeviceFileEvents directly records the file modifications encryption produces.
- ✗
DeviceProcessEvents
Why it's wrong here
DeviceProcessEvents logs process creation, command lines and parent-child relationships, not file writes, so it cannot show which files were encrypted. It is tempting because ransomware spawns processes such as vssadmin or cipher, but those are precursor indicators; DeviceFileEvents captures the actual file modification and renaming events.
- ✓
DeviceFileEvents
Why this is correct
DeviceFileEvents records file creation, modification and renaming activity from Defender for Endpoint, capturing the rapid, high-volume write and rename operations ransomware performs during encryption. This directly satisfies the stem's requirement to detect file encryption events, unlike tables covering process, network or registry activity.
- ✗
DeviceRegistryEvents
Why it's wrong here
DeviceRegistryEvents records registry key creation and modification, not file writes, so encryption of documents would not appear there. It is tempting because ransomware does alter registry keys for persistence, but detecting the encryption itself requires DeviceFileEvents, which logs file creation, modification and renaming.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.