Courseiva
hardMultiple Choice

SC-200 Practice Question: A security analyst is investigating a suspected…

A security analyst is investigating a suspected lateral movement attack in Microsoft 365 Defender. The analyst wants to identify all devices where a specific user account (user@contoso.com) had an interactive logon, and then check which of those devices subsequently made outbound RDP connections to other internal IP addresses. Which KQL query approach is most efficient to find this chain?

⚠ Common exam trap

A common mix-up: candidates choose Option B, thinking IdentityLogonEvents covers all logons, but it lacks device-level details and LogonType filtering, which are essential for identifying interactive logons on a specific machine in a lateral movement investigation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Join DeviceLogonEvents (where AccountName == 'user@contoso.com' and LogonType == 'Interactive') with DeviceNetworkEvents (where RemotePort == 3389) on DeviceName, and filter for NetworkEvents timestamp > LogonEvents timestamp

It directly correlates interactive logon events (DeviceLogonEvents with LogonType == 'Interactive') for the specific user with subsequent outbound RDP connections (DeviceNetworkEvents with RemotePort == 3389) on the same device, using a join on DeviceName and a timestamp filter to ensure the network event occurs after the logon. This approach efficiently identifies the lateral movement chain by linking the initial compromise device to the target device via RDP, leveraging the native schema of Microsoft 365 Defender.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Join DeviceLogonEvents (where AccountName == 'user@contoso.com' and LogonType == 'Interactive') with DeviceNetworkEvents (where RemotePort == 3389) on DeviceName, and filter for NetworkEvents timestamp > LogonEvents timestamp

    Why this is correct

    This query correctly links the user's interactive logon on a device to subsequent outbound RDP traffic to port 3389 from that same device. The timestamp filter ensures the network event occurred after the logon, proving the user (or attacker) established an interactive session before initiating the remote desktop connection. This temporal and device-based correlation is the essential pattern for detecting lateral movement via RDP.

  • ✗

    Use IdentityLogonEvents to find the user's logons and join with DeviceNetworkEvents on IP address

    Why it's wrong here

    IdentityLogonEvents captures Microsoft Entra ID sign-in events, but these often reflect cloud, non-interactive, or delegated authentication and do not confirm a local interactive logon on the specific endpoint. Joining on IP address alone is unreliable because IPs can be NATed or shared, and the join yields no DeviceName or timestamp alignment to prove the user actually initiated RDP from that host. This approach lacks the device-level context needed to establish a lateral movement chain.

  • ✗

    Query EmailEvents to find emails sent from the user and then check DeviceNetworkEvents on the sender device

    Why it's wrong here

    EmailEvents describes message delivery and metadata like sender, recipient, and subject, but it contains no logon or network connection data for the endpoint. Checking DeviceNetworkEvents on the sender's device based on an email does not show the user ever authenticated interactively or that any RDP traffic originated after such a logon. Lateral movement via RDP is a device and network artifact, not an email behavior, so this query cannot sequence the required logon-to-network events.

  • ✗

    Union DeviceLogonEvents and DeviceNetworkEvents, then summarize by DeviceName and filter for the user

    Why it's wrong here

    A UNION simply stacks rows from DeviceLogonEvents and DeviceNetworkEvents into one result set, preserving each row's original columns but creating no relationship between them. Summarizing by DeviceName and filtering for the user discards the logon type and port information, and without a timestamp join you cannot tell whether the RDP connection happened after the interactive logon. This produces an unverified list of device and user activity, not evidence of lateral movement.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.