SC-200 • Practice Test 6
Free SC-200 practice test — 10 questions with explanations. Set 6. No signup required.
A security analyst is investigating an advanced persistent threat campaign that involves lateral movement using RDP. The analyst suspects that an attacker uses RDP from DeviceA to DeviceB, and then within a few minutes executes a malicious PowerShell script on DeviceB. The analyst wants to create a custom detection rule in Microsoft 365 Defender that triggers when this pattern occurs. Which KQL query pattern should be used to correlate these events across devices?
Choose an answer to begin — your selection is scored in the full session.
10 questions · instant feedback and full explanations after every question.