Courseiva
Perform threat hunting →hardMultiple Choice

SC-200 Perform threat hunting Practice Question

An organization uses Microsoft Defender for Endpoint (MDE) to hunt for signs of credential dumping. An analyst runs a custom advanced hunting query that searches for processes accessing LSASS.exe. The query uses DeviceProcessEvents and DeviceFileEvents. The analyst notices that some known credential dumping tools are detected, but they want to find previously unknown variants. Which approach should the analyst take to improve the hunt?

⚠ Common exam trap

SC-200 often tests the distinction between signature-based detection (which only catches known threats) and behavior-based hunting (which finds unknown variants) — candidates who default to 'add more indicators' fall for the signature trap.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Look for anomalous LSASS access patterns using process lineage and call stacks.

To catch previously unknown credential-dumping variants, the analyst must move beyond signature and file-reputation indicators and instead hunt for behavioral anomalies in how processes access LSASS. Analyzing process lineage (which parent spawned the accessing process) and call stacks (which modules and functions are invoking LSASS) surfaces suspicious patterns like unsigned binaries, unusual parent-child relationships, or direct syscalls that signature-based detections miss. This is the essence of hypothesis-driven, behavior-based hunting in MDE advanced hunting.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable LSASS auditing via Windows Security Event Log.

    Why it's wrong here

    Enabling LSASS auditing populates Windows Security event logs, which the query's DeviceProcessEvents and DeviceFileEvents tables do not ingest, so the hunt gains no new process-access visibility. It tempts for compliance auditing, where SecurityEvent LSASS access events are the standard source.

  • ✗

    Focus on file reputation data to exclude clean files.

    Why it's wrong here

    File reputation excludes files already classified as clean, which removes data rather than revealing novel credential-dumping behaviour; unknown variants typically carry no reputation verdict anyway. It tempts as noise reduction, which is valid when triaging high-volume alerts rather than broadening detection coverage.

  • ✗

    Add more signature-based indicators to the query.

    Why it's wrong here

    Signature-based indicators match artefacts of tools already known, so they cannot surface previously unknown variants; the hunt needs behavioural signals instead. It tempts because custom indicators are the normal route for encoding threat intelligence, but they inherently describe known-bad patterns.

  • ✓

    Look for anomalous LSASS access patterns using process lineage and call stacks.

    Why this is correct

    Signature-based matching only catches known tools, so behavioural analysis is needed. Correlating process lineage and call stacks exposes anomalous LSASS access by novel variants, satisfying the requirement to detect previously unknown credential dumping tools rather than relying on known indicators.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.