Courseiva
Perform threat hunting →mediumMultiple Choice

SC-200 Perform threat hunting Practice Question

You are investigating a potential ransomware incident in Microsoft Defender XDR. You need to identify files that have been modified with a known ransomware extension across all devices. Which advanced hunting operator should you use to search for file names ending with '.locked' in the DeviceFileEvents table?

⚠ Common exam trap

The trap here is using contains instead of endswith, which can lead to false positives by matching the substring anywhere in the file name.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

endswith

To find files with a specific extension, you need to match the end of the file name. The endswith operator is designed for this purpose and will correctly identify files ending with '.locked'. Using contains might match unintended substrings, and startswith would look at the wrong end of the string.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    endswith

    Why this is correct

    The endswith operator checks if a string ends with a specified suffix. Using endswith '.locked' on the FileName column will accurately identify files that have been renamed with the '.locked' extension, which is characteristic of ransomware encryption. This operator is case-insensitive and efficient for this purpose.

  • ✗

    contains

    Why it's wrong here

    The contains operator checks if a string contains a specified substring anywhere, not just at the end. Using contains '.locked' would also match files like 'mylocked.txt' or 'locked_file.doc', which could introduce false positives. For a suffix match, a more precise operator is needed to avoid unnecessary noise in the results.

  • ✗

    matches regex

    Why it's wrong here

    The matches regex operator allows pattern matching using regular expressions, which could be used to detect file extensions. However, for a simple suffix match like '.locked', it is overkill and may be less performant. The endswith operator is specifically designed for this exact use case and is simpler to write and understand.

  • ✗

    startswith

    Why it's wrong here

    The startswith operator checks if a string begins with a specified prefix. Ransomware typically appends an extension to the original file name, so the malicious indicator appears at the end of the file name, not the beginning. Using startswith would miss files like 'document.docx.locked' because they do not start with '.locked'.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.