Courseiva
Perform threat hunting →easyMultiple Choice

SC-200 Perform threat hunting Practice Question

You are hunting for suspicious scheduled tasks that could be used for persistence. Which Microsoft 365 Defender advanced hunting table contains information about scheduled tasks?

⚠ Common exam trap

SC-200 often tests the distinction between process execution and system event logging, causing candidates to mistakenly choose DeviceProcessEvents when asked about scheduled task creation, even though the actual task registration is recorded in DeviceEvents.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

DeviceEvents

DeviceEvents in Microsoft 365 Defender advanced hunting is the correct table because it captures a wide range of system and security events, including scheduled task creation, modification, and deletion. Specifically, it logs events like 'ScheduledTaskCreated' and 'ScheduledTaskModified' under the ActionType column, which are essential for detecting persistence mechanisms. Other tables focus on different telemetry: IdentityLogonEvents for authentication, DeviceNetworkEvents for network connections, and DeviceProcessEvents for process creation. Thus, DeviceEvents is the only table that directly contains scheduled task information.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    IdentityLogonEvents

    Why it's wrong here

    IdentityLogonEvents is an advanced hunting table that collects authentication and logon activity from Microsoft Entra ID and Active Directory, including success/failure and sign-in type. It does not ingest Windows event ID 4698 or any other scheduled task registration events. While a suspicious task's creation might be tied to a specific account, this table only shows logon activity, not configuration changes to the task scheduler. Therefore it is not the correct table for discovering the initial task creation itself.

  • ✓

    DeviceEvents

    Why this is correct

    DeviceEvents is the correct table because it contains a wide range of Windows security events, including Event ID 4698 which is specifically the creation of a scheduled task. This table ingests events from the Windows Event Log and is the primary place to hunt for persistence mechanisms like new scheduled tasks. You can also find related events like task updates (4702) and deletions (4699) here. So for identifying suspicious scheduled task creation, DeviceEvents is the authoritative source.

  • ✗

    DeviceNetworkEvents

    Why it's wrong here

    DeviceNetworkEvents captures outbound and inbound network connection attempts made by processes running on devices, such as source IP, destination, and protocol. It does not include scheduled task creation events, because those are configuration changes rather than network activity. A scheduled task could later initiate a network connection after execution, but that would only show up after the fact, not when the task is created. Thus this table is useful for tracking command-and-control traffic, but not for the initial suspicious task registration.

  • ✗

    DeviceProcessEvents

    Why it's wrong here

    DeviceProcessEvents records process creation and execution events, including parent and command line details, but it does not log the registration of a scheduled task. When the scheduled task is created, no process is spawned; the task definition is simply written to the system's task store. Later, when the task triggers, it will appear here as a process launch, but that is the execution phase, not creation. Therefore this table helps you observe the behavior of a task, but it is not the right source for seeing Event ID 4698.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.