Courseiva
Perform threat hunting →easyMultiple Choice

SC-200 Perform threat hunting Practice Question

A threat hunter in Microsoft Sentinel wants to detect attempts to disable security logging on Windows servers using a KQL query. Which Windows Event ID should the query filter on to capture security log clearing events?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

1102

Event ID 1102 in the Windows Security log indicates the security log was cleared, which is a common technique used by attackers to cover their tracks. Option A (4688) is for process creation. Option B (4624) is for successful logon. Option C (5145) is for network share access. Therefore, only Option D (1102) correctly captures security log clearing events.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    4688

    Why it's wrong here

    Event ID 4688 records process creation, so it captures new processes rather than the security event log being cleared. It is tempting because 4688 is widely used for detecting suspicious command execution, but the log-clearing event this hunt targets is 1102, not process creation.

  • ✗

    4624

    Why it's wrong here

    Event ID 4624 records successful account logons, so filtering on it returns authentication activity rather than log-clearing. It is tempting because 4624 is heavily used in Sentinel sign-in analytics, but the security log being cleared generates 1102, which is the event this hunt requires.

  • ✗

    5145

    Why it's wrong here

    Event ID 5145 logs detailed file share access attempts, capturing object access rather than the security log being cleared. It is tempting because 5145 is a common Windows security auditing event used in lateral-movement hunts, but log clearing is recorded as 1102, not 5145.

  • ✓

    1102

    Why this is correct

    Event ID 1102 records the Windows security audit log being cleared, written to the Security log whenever someone runs wevtutil or clears it via Event Viewer. Filtering on 1102 in the KQL query therefore surfaces exactly the anti-forensic behaviour the hunter targets, satisfying the requirement to detect security logging being disabled on those servers.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.