SC-200 Perform threat hunting Practice Question
You are investigating a potential ransomware incident in Microsoft Defender XDR. You need to identify files that have been modified with a known ransomware extension across all devices. Which advanced hunting operator should you use to search for file names ending with '.locked' in the DeviceFileEvents table?
⚠ Common exam trap
The trap here is using contains instead of endswith, which can lead to false positives by matching the substring anywhere in the file name.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
endswith
To find files with a specific extension, you need to match the end of the file name. The endswith operator is designed for this purpose and will correctly identify files ending with '.locked'. Using contains might match unintended substrings, and startswith would look at the wrong end of the string.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
endswith
Why this is correct
The endswith operator checks if a string ends with a specified suffix. Using endswith '.locked' on the FileName column will accurately identify files that have been renamed with the '.locked' extension, which is characteristic of ransomware encryption. This operator is case-insensitive and efficient for this purpose.
- ✗
contains
Why it's wrong here
The contains operator checks if a string contains a specified substring anywhere, not just at the end. Using contains '.locked' would also match files like 'mylocked.txt' or 'locked_file.doc', which could introduce false positives. For a suffix match, a more precise operator is needed to avoid unnecessary noise in the results.
- ✗
matches regex
Why it's wrong here
The matches regex operator allows pattern matching using regular expressions, which could be used to detect file extensions. However, for a simple suffix match like '.locked', it is overkill and may be less performant. The endswith operator is specifically designed for this exact use case and is simpler to write and understand.
- ✗
startswith
Why it's wrong here
The startswith operator checks if a string begins with a specified prefix. Ransomware typically appends an extension to the original file name, so the malicious indicator appears at the end of the file name, not the beginning. Using startswith would miss files like 'document.docx.locked' because they do not start with '.locked'.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.