Courseiva
Perform threat hunting →easyMultiple Choice

SC-200 Perform threat hunting Practice Question

A security analyst is hunting for signs of credential dumping using Microsoft Defender for Endpoint. Which advanced hunting query should the analyst use to detect the use of Mimikatz?

⚠ Common exam trap

The trap is that candidates pick the table that sounds most 'security-related' (registry or network) instead of recognizing that tool execution and command-line arguments are always captured in DeviceProcessEvents — the exam tests whether you know which MDE table holds which telemetry type.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

DeviceProcessEvents where ProcessCommandLine contains 'mimikatz'

Mimikatz is executed as a process, and its invocation (e.g., 'mimikatz.exe', 'Invoke-Mimikatz', or sekurlsa::logonpasswords) appears in the process command line. Microsoft Defender for Endpoint's DeviceProcessEvents table captures ProcessCommandLine, making it the correct table for detecting execution-based credential dumping. This is the standard hunting pattern for tool-name or command-line-based detection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    DeviceRegistryEvents where RegistryKey contains 'mimikatz'

    Why it's wrong here

    DeviceRegistryEvents track modifications to the Windows registry, but Mimikatz primarily operates in memory and does not write keys named after itself during credential dumping. While an attacker could configure persistence via the registry, that would be a later, separate action, not the dumping activity itself. Consequently, a query searching the RegistryKey field for 'mimikatz' rarely yields results and fails to capture the execution of the tool.

  • ✓

    DeviceProcessEvents where ProcessCommandLine contains 'mimikatz'

    Why this is correct

    DeviceProcessEvents capture process creation events, including the full command line, which is exactly where Mimikatz's execution appears—for example, 'mimikatz.exe privilege::debug sekurlsa::logonpasswords'. Searching ProcessCommandLine for 'mimikatz' directly detects the tool being run, even if the executable is renamed, as long as the command line includes the name. This is the most dependable hunting query because credential dumping requires process execution, and process creation logs are the primary telemetry for that activity.

  • ✗

    DeviceFileEvents where FileName contains 'mimikatz'

    Why it's wrong here

    DeviceFileEvents record file creation, renaming, or writing, so a query on FileName containing 'mimikatz' could identify when the binary is dropped to disk. However, this only proves the file exists, not that it was executed—attackers often rename the executable to avoid detection, so the filename might not contain 'mimikatz' anyway. Process creation events, by contrast, capture actual execution, making them superior for hunting credential-dumping tools.

  • ✗

    DeviceNetworkEvents where RemoteIP contains 'mimikatz'

    Why it's wrong here

    DeviceNetworkEvents log network connections, and the RemoteIP field stores IP addresses, not arbitrary strings like 'mimikatz'. A 'contains' filter on RemoteIP would never match a tool name, and even if it did, Mimikatz typically dumps credentials locally from LSASS without generating distinctive network traffic. This query is fundamentally mistyped and would produce no relevant results; instead, one should focus on local process execution or, if exfiltration is suspected, correlate with outbound destination IPs.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.