SC-200 Manage a security operations environment Practice Question
Your organization uses Microsoft Defender XDR. You need to investigate a potential ransomware incident that has affected multiple devices. The security team wants to identify the initial access vector. Which advanced hunting table should you query to find the process that initiated the encryption?
⚠ Common exam trap
It's easy for candidates to confuse the artifact of encryption (file changes in DeviceFileEvents) with the action that caused it (process creation in DeviceProcessEvents), leading them to choose DeviceFileEvents instead of the correct table for tracing the initial access vector.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DeviceProcessEvents
DeviceProcessEvents logs process creation events, including the command line and parent process details. To identify the initial access vector in a ransomware incident, you need to trace the process tree back to the executable that launched the encryption process, which is precisely what this table captures.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
DeviceRegistryEvents
Why it's wrong here
DeviceRegistryEvents records changes to the Windows registry, such as modification of Run keys, services, or security settings. While ransomware may write to the registry for persistence or to disable protections, this telemetry does not capture the creation of a process; the initial executable that launched the encryption routine is therefore invisible in this table. For that reason, registry events cannot be used to identify the process responsible for the attack.
- ✗
DeviceFileEvents
Why it's wrong here
DeviceFileEvents tracks file creation, deletion, and modification, so it will show encrypted file artifacts (e.g., .encrypted extensions) or overwritten documents, but it does not record which process performed those operations. The table's schema lacks the parent process ancestry needed to trace the action back to the initial executable. While a SOC might use file events to detect symptoms, they cannot pinpoint the originating process.
- ✗
DeviceNetworkEvents
Why it's wrong here
DeviceNetworkEvents focuses on network communication, including source/destination IPs, ports, and protocols, and it is useful for spotting command-and-control beacons or data exfiltration. Although it includes the process that initiated the connection, the event is only generated when a network activity occurs; the initial process creation and command line that started the encryption remain outside its scope. Therefore, network events alone cannot identify the initial process.
- ✓
DeviceProcessEvents
Why this is correct
DeviceProcessEvents captures every process creation, along with the file name, command line, and parent process PID, enabling analysts to build a process tree from the initial point of execution. This table is the authoritative source for tracking the initial process — such as a malicious binary launched from an Office macro — because it records the moment the process became active. By querying DeviceProcessEvents, incident responders can trace the parent process chain and determine exactly which executable initiated the encryption.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.