Courseiva
Perform threat hunting →easyMultiple Choice

SC-200 Perform threat hunting Practice Question

You are hunting for signs of ransomware in your environment using Microsoft 365 Defender. Which advanced hunting table should you primarily query to detect file encryption events?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

DeviceFileEvents

DeviceFileEvents captures file creation, modification, and deletion events, which are typical for ransomware encryption. Option A (DeviceNetworkEvents) is wrong because it captures network connections, not file events. Option B (DeviceProcessEvents) is wrong because it captures process creation and termination, not file events. Option D (DeviceRegistryEvents) is wrong because it captures registry modifications, not file events.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    DeviceNetworkEvents

    Why it's wrong here

    DeviceNetworkEvents captures connection attempts, DNS lookups and listening ports, not local file operations, so encryption activity is invisible. It is tempting because ransomware contacts command-and-control servers, but that network signal is indirect; DeviceFileEvents directly records the file modifications encryption produces.

  • ✗

    DeviceProcessEvents

    Why it's wrong here

    DeviceProcessEvents logs process creation, command lines and parent-child relationships, not file writes, so it cannot show which files were encrypted. It is tempting because ransomware spawns processes such as vssadmin or cipher, but those are precursor indicators; DeviceFileEvents captures the actual file modification and renaming events.

  • ✓

    DeviceFileEvents

    Why this is correct

    DeviceFileEvents records file creation, modification and renaming activity from Defender for Endpoint, capturing the rapid, high-volume write and rename operations ransomware performs during encryption. This directly satisfies the stem's requirement to detect file encryption events, unlike tables covering process, network or registry activity.

  • ✗

    DeviceRegistryEvents

    Why it's wrong here

    DeviceRegistryEvents records registry key creation and modification, not file writes, so encryption of documents would not appear there. It is tempting because ransomware does alter registry keys for persistence, but detecting the encryption itself requires DeviceFileEvents, which logs file creation, modification and renaming.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.