Practice modeFree teaserMicrosoft · Microsoft Security Operations Analyst (SC-200) — Practice Exam 3
Question 1 of 10Perform threat huntingSelect ONE answer
You want to identify devices where a process spawned cmd.exe from a Microsoft Office process within the last 7 days. Which KQL pattern fits?
Pick an option to reveal the answer.
Keyboard: ← → to navigate · F to flag
© 2026 Tertiary Infotech Academy Pte Ltd. All rights reserved.
Powered by Tertiary Infotech Academy Pte Ltd