SC-200 Perform threat hunting Practice Question
A threat hunter in Microsoft Sentinel wants to detect attempts to disable security logging on Windows servers using a KQL query. Which Windows Event ID should the query filter on to capture security log clearing events?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
1102
Event ID 1102 in the Windows Security log indicates the security log was cleared, which is a common technique used by attackers to cover their tracks. Option A (4688) is for process creation. Option B (4624) is for successful logon. Option C (5145) is for network share access. Therefore, only Option D (1102) correctly captures security log clearing events.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
4688
Why it's wrong here
Event ID 4688 records process creation, so it captures new processes rather than the security event log being cleared. It is tempting because 4688 is widely used for detecting suspicious command execution, but the log-clearing event this hunt targets is 1102, not process creation.
- ✗
4624
Why it's wrong here
Event ID 4624 records successful account logons, so filtering on it returns authentication activity rather than log-clearing. It is tempting because 4624 is heavily used in Sentinel sign-in analytics, but the security log being cleared generates 1102, which is the event this hunt requires.
- ✗
5145
Why it's wrong here
Event ID 5145 logs detailed file share access attempts, capturing object access rather than the security log being cleared. It is tempting because 5145 is a common Windows security auditing event used in lateral-movement hunts, but log clearing is recorded as 1102, not 5145.
- ✓
1102
Why this is correct
Event ID 1102 records the Windows security audit log being cleared, written to the Security log whenever someone runs wevtutil or clears it via Event Viewer. Filtering on 1102 in the KQL query therefore surfaces exactly the anti-forensic behaviour the hunter targets, satisfying the requirement to detect security logging being disabled on those servers.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.