Courseiva

CCNA Perform threat hunting Questions

75 of 178 questions · Page 1/3 · Perform threat hunting · Answers revealed

1
Multi-Selecteasy

Which TWO built-in Microsoft Sentinel hunting queries are useful for detecting signs of compromised credentials?

Select 2 answers
A.Baseline of user behavior
B.Anomalous logon location
C.Brute force attempt against user accounts
D.Deleted user account
E.New user account creation
AnswersB, C

Anomalous logon location is one of the built-in hunting queries in Microsoft Sentinel, found in the Hunting blade. It uses KQL to analyze sign-in logs, detecting attempts from unexpected geographies or IP addresses, which may indicate compromised credentials or impossible travel. This query is part of Sentinel's predefined hunting pack and is a strong indicator of credential misuse.

Why this answer

Option B, 'Anomalous logon location,' is correct because it flags authentication events where a user signs in from an unusual or unexpected geographic location, which is a classic indicator that credentials have been stolen and are being used by an attacker from a different region. Option C, 'Brute force attempt against user accounts,' is correct because it detects repeated failed authentication attempts followed by a success, directly surfacing password-guessing activity that results in compromised credentials. Option A, 'Baseline of user behavior,' is a general behavioral analytics query that establishes normal activity patterns rather than specifically detecting credential compromise.

Option D, 'Deleted user account,' relates to account lifecycle or destructive actions, not credential theft. Option E, 'New user account creation,' indicates persistence or privilege escalation via a newly created account, not the compromise of existing credentials.

Exam trap

SC-200 often tests whether candidates confuse persistence-related queries (new/deleted accounts) with credential compromise indicators (anomalous logon, brute force), so knowing the exact built-in query names and their purpose is essential.

2
MCQhard

Your organization uses Microsoft Sentinel and Microsoft Defender XDR. You want to create a hunting query that finds users who have accessed a high number of distinct Azure resources within a short time frame, which may indicate credential theft. Which KQL query would be most effective?

A.AzureActivity | summarize dcount(Resource) by bin(TimeGenerated, 1m), Caller
B.AzureActivity | summarize count() by Caller | where count_ > 20
C.AzureActivity | summarize dcount(OperationName) by Caller, bin(TimeGenerated, 1h) | where dcount_OperationName > 20
D.AzureActivity | where TimeGenerated > ago(1d) | summarize dcount(Resource) by Caller, bin(TimeGenerated, 1h) | where dcount_Resource > 20
AnswerD

This query correctly isolates the last 24 hours of activity, groups events by each caller (user or service principal) and by one-hour time bins, and then computes the distinct count of Resource values—the full Azure resource IDs—for each group. The filter dcount_Resource > 20 surfaces users that accessed an unusually high number of distinct Azure resources within a single hour, a pattern consistent with an attacker rapidly enumerating the environment to find high-value targets. This approach balances sensitivity and performance, and it directly maps to the MITRE ATT&CK technique T1087 (Account Discovery) or T1526 (Cloud Service Discovery) when run as a scheduled Sentinel analytics rule.

Why this answer

It uses the AzureActivity table to count distinct resources per user per hour, filtering for those with more than 20 resources. Option A is wrong because it uses a 1-minute bucket, too granular for meaningful hunting. Option B is wrong because it counts operations, not distinct resources.

Option C is wrong because it counts distinct operation names, not resources.

3
MCQmedium

Refer to the exhibit. You are investigating a user account that shows multiple logons to the Azure Portal from various countries within a short time. The query returns no results despite known logons. What is the most likely issue?

A.The Timestamp filter should be Timestamp > ago(7d) but instead it's written incorrectly.
B.The AccountUpn field is not present in IdentityLogonEvents.
C.The Application filter should be 'Azure Portal' in a different case.
D.IdentityLogonEvents does not contain Azure Portal logon events; use AADSignInEventsBeta instead.
AnswerD

IdentityLogonEvents captures only on-premises Active Directory and AD FS authentication, not cloud sign-ins. Azure Portal logons are recorded in Microsoft Entra ID sign-in logs, surfaced in Microsoft Defender for Cloud Apps through the AADSignInEventsBeta table. Querying the wrong table explains the empty result despite known portal logons.

Why this answer

IdentityLogonEvents in Microsoft Defender for Identity (MDI) captures on-premises Active Directory authentication events, not Azure AD (Entra ID) sign-in events. Azure Portal logons are Azure AD sign-in events, which are stored in the AADSignInEventsBeta table in Microsoft 365 Defender advanced hunting. Therefore, querying IdentityLogonEvents for Azure Portal logons returns no results, and the correct table is AADSignInEventsBeta.

Exam trap

SC-200 often tests the distinction between on-premises identity tables (IdentityLogonEvents) and cloud identity tables (AADSignInEventsBeta), so candidates who assume all logon events are in one table pick the wrong filter or field.

How to eliminate wrong answers

Option A is wrong because the Timestamp filter syntax 'ago(7d)' is valid in Kusto Query Language; the issue is not the time filter but the wrong table. Option B is wrong because AccountUpn is a valid field in IdentityLogonEvents; the field exists, but the table does not contain Azure Portal logon events. Option C is wrong because Kusto string comparisons are case-sensitive by default, but the Application field in IdentityLogonEvents does not capture Azure Portal logons at all, so changing case would not help.

4
Multi-Selecteasy

Which THREE actions are recommended when conducting a threat hunt for compromised identities using Microsoft Sentinel UEBA?

Select 3 answers
A.Search for access to applications the user does not normally use
B.Query DNS logs for unusual domain resolutions
C.Look for multiple failed logon attempts followed by a successful one
D.Investigate changes to firewall rules
E.Review UEBA anomalies for unusual logon times or locations
AnswersA, C, E

Checking for access to applications outside a user's historical usage is a high-fidelity indicator of identity compromise because attackers rarely mimic the exact application footprint of the legitimate user. In Microsoft Sentinel, you can use UEBA data or sign-in logs to build a baseline and then alert when a newly logged-on application has no prior events for that user. This type of anomaly is less likely to be a false positive than raw volume-based signals, because it directly reflects the attacker's post-authentication intent.

Why this answer

Option A is correct because Microsoft Sentinel UEBA baselines each user's normal application usage, so access to applications the user does not normally use is a high-signal anomaly indicating possible credential compromise or token theft. Option C is correct because a burst of failed logon attempts followed by a successful one is the classic pattern of a brute-force or password-spray attack that ends in a valid session, and UEBA surfaces this as an anomalous sign-in sequence. Option E is correct because UEBA specifically models per-user behavioral baselines for logon times and locations, so deviations such as impossible travel or off-hours sign-ins are core indicators of a compromised identity.

Option B does not belong because DNS log analysis targets command-and-control or malware beaconing rather than identity compromise, and it is not a UEBA identity-focused action. Option D does not belong because firewall rule changes are a network/infrastructure configuration concern, not an identity behavior anomaly tracked by UEBA.

Exam trap

SC-200 often tests the scope of UEBA — candidates pick network-layer or configuration hunts (DNS logs, firewall rules) that sound like threat hunting but are not identity-focused UEBA actions.

5
Multi-Selecthard

Which THREE actions are part of the threat hunting process in Microsoft Defender XDR?

Select 3 answers
A.Configure automated response actions
B.Investigate entities found in the results
C.Query advanced hunting using KQL
D.Formulate a hypothesis based on threat intelligence
E.Set data retention policies for hunting data
AnswersB, C, D

Investigating entities found in the query results is a defining threat-hunting action because it requires pivoting from raw data to the entity pages for users, devices, files, IPs, or mailboxes, then reviewing timelines, related alerts, and correlated events to decide whether the behavior is genuinely malicious. This validation step is what confirms or refutes the original hypothesis and reveals the scope of the threat. Without entity-level investigation, a hunter cannot distinguish a true positive from a benign anomaly or a false positive.

Why this answer

Threat hunting in Microsoft Defender XDR follows a hypothesis-driven, iterative process, and option D ("Formulate a hypothesis based on threat intelligence") is correct because a hunt begins by defining a specific, testable hypothesis derived from threat intel, known TTPs, or an anomaly to guide the search. Option C ("Query advanced hunting using KQL") is correct because the hypothesis is tested by running KQL queries in Advanced Hunting against tables such as DeviceProcessEvents, DeviceNetworkEvents, and EmailEvents to surface matching telemetry. Option B ("Investigate entities found in the results") is correct because any suspicious processes, devices, IPs, or accounts returned by the query are then pivoted on and investigated (e.g., via the entity page, timeline, and incident correlation) to confirm or refute the hypothesis.

Option A ("Configure automated response actions") is not part of hunting itself; automated response is configured through automated investigation and response (AIR) and custom detection/action settings, which are remediation, not hunting. Option E ("Set data retention policies for hunting data") is not part of the hunting process; retention is governed by tenant/Advanced Hunting data retention settings and is an administrative configuration rather than a hunting step.

Exam trap

SC-200 often tests whether candidates conflate threat hunting with incident response or data governance — the trap is selecting 'configure automated response actions' because it sounds like part of the security workflow.

6
MCQmedium

You are a security analyst using Microsoft Sentinel. You want to proactively search for signs of a specific threat actor known to use PowerShell encoded commands. Which hunting technique is most appropriate?

A.Create an analytics rule to trigger an alert when PowerShell encoded commands are detected.
B.Create a watchlist of known malicious IPs and correlate with PowerShell events.
C.Enable UEBA to detect anomalous PowerShell usage.
D.Use a hunting query in the Microsoft Sentinel hunting blade to search for PowerShell encoded commands.
AnswerD

Hunting queries in the Microsoft Sentinel hunting blade let analysts proactively search logs for indicators such as PowerShell encoded commands, matching the requirement to seek out a known threat actor's techniques rather than wait for an alert.

Why this answer

Hunting queries in Microsoft Sentinel allow proactive searching for suspicious patterns. Option D is correct because it directly aligns with the need to create a custom KQL query to detect encoded PowerShell commands in the hunting blade. Option A is incorrect because analytics rules trigger alerts after detection, not for proactive hunting.

Option B is incorrect because a watchlist is used for correlation with known indicators, not proactive hunting. Option C is incorrect because UEBA identifies anomalies, not specific threat actor techniques.

7
MCQeasy

You are hunting for signs of credential theft in Microsoft Defender XDR. Which advanced hunting table is most appropriate to investigate suspicious logon events?

A.DeviceNetworkEvents
B.DeviceProcessEvents
C.EmailEvents
D.IdentityLogonEvents
AnswerD

IdentityLogonEvents records authentication activity across Microsoft Entra ID and on-premises identity infrastructure, including logon type, application and failure reasons. This makes it the appropriate table for surfacing anomalous or suspicious logon patterns indicative of credential theft.

Why this answer

IdentityLogonEvents contains authentication logs, which are most relevant for investigating suspicious logon events and credential theft. Option A (DeviceNetworkEvents) is for network connections. Option B (DeviceProcessEvents) is for process events.

Option C (EmailEvents) is for email records.

8
Multi-Selecteasy

Which TWO actions are essential for configuring Microsoft Sentinel to support effective threat hunting?

Select 2 answers
A.Connect Microsoft 365 data sources (e.g., Office 365, Entra ID, Defender for Cloud Apps)
B.Create a Watchlist that maps user names to email addresses
C.Enable User and Entity Behavior Analytics (UEBA) in Microsoft Sentinel
D.Configure custom analytics rules for every MITRE ATT&CK technique
E.Install Sysmon on all domain controllers
AnswersA, C

Connecting Microsoft 365 data sources is essential because Microsoft Sentinel hunting queries must run against ingested telemetry from these connectors. Office 365 and Entra ID provide audit logs, sign-in logs, and email/Teams activity, and Defender for Cloud Apps adds SaaS shadow IT and session data. Without these sources, KeyVault events, IdentityInfo, and other UEBA-dependent tables remain empty, so hunting for malicious user behavior is impossible.

Why this answer

Enabling User and Entity Behavior Analytics (UEBA) provides baselines for hunting anomalies, and connecting Microsoft 365 data sources provides rich data for hunting. Customizing analytics rules is for detection, not hunting; Sysmon is not required; Watchlists are helpful but not essential for basic hunting setup.

9
Multi-Selectmedium

Which THREE of the following are valid sources of data that a threat hunter can use in Microsoft Sentinel for hunting? (Choose three.)

Select 3 answers
A.Microsoft Entra ID audit logs
B.Azure Cost Management data
C.Azure DevOps pipelines
D.Microsoft 365 audit logs
E.AWS CloudTrail logs
AnswersA, D, E

Microsoft Entra ID audit logs record sign-in and directory change activity, and Microsoft Sentinel ingests them through the Entra ID data connector. They surface authentication anomalies and privilege changes, giving threat hunters a native identity-based data source for correlating suspicious account behaviour across the environment.

Why this answer

Microsoft Sentinel ingests Microsoft Entra ID audit logs through the Azure Active Directory (now Entra ID) data connector, which records sign-in and directory activity and is a legitimate hunting source, so option A is correct. Microsoft 365 audit logs are collected via the Office 365 data connector (using the Management Activity API) and provide Exchange, SharePoint, Teams, and general audit events usable for hunting, making option D correct. AWS CloudTrail logs are supported through the Amazon Web Services S3/CloudTrail connector, which pulls API activity into Sentinel for cross-cloud hunting, so option E is correct.

Azure Cost Management data (option B) is billing and cost-analysis telemetry, not security event data ingested as a hunting table in Sentinel, and Azure DevOps pipelines (option C) are CI/CD build/release processes rather than a native Sentinel hunting data source, so neither belongs.

10
MCQhard

You are conducting a threat hunt in Microsoft Defender XDR and want to identify devices that have recently communicated with a known C2 server IP address. Which advanced hunting table should you query?

A.DeviceNetworkEvents
B.DeviceFileEvents
C.DeviceLogonEvents
D.DeviceProcessEvents
AnswerA

DeviceNetworkEvents is the correct table for C2 hunting because it specifically records network connection attempts, including source and destination IP addresses, ports, protocols, and remote URLs. Unlike file or process events, this table lets you directly search for outbound connections to known malicious or suspicious infrastructure, which is the core signature of command-and-control communications. Without this telemetry, you cannot definitively identify the network egress point to a C2 server.

Why this answer

EviceNetworkEvents (Option A) because this table contains network connection events including destination IP addresses, ports, and protocols. It is used to identify network communications with suspicious IPs such as C2 servers. DeviceProcessEvents (Option D) is for process creation events, DeviceLogonEvents (Option C) is for authentication events, and DeviceFileEvents (Option B) is for file system events.

Only DeviceNetworkEvents provides the necessary network traffic information for threat hunting in Microsoft Defender XDR.

11
MCQhard

A threat hunter is using Microsoft Sentinel and wants to leverage machine learning to detect anomalous behavior in Azure subscription activity. Which analytics rule template should the hunter use?

A.Anomalous Sign-In Locations
B.Anomalous Azure Operations
C.Anomalous User Behavior
D.Lateral Movement Detection
AnswerB

The Anomalous Azure Operations rule is a built-in Microsoft Sentinel analytics rule that uses machine learning to analyze AzureActivity logs and flag unusual operations within an Azure subscription, such as atypical role assignments, resource deployments, or modification of critical settings. Unlike other anomaly rules, it specifically targets the Azure control plane and is driven by the AzureActivity data connector. This rule is the correct choice for a threat hunter seeking to uncover abnormal Azure subscription operations.

Why this answer

The 'Anomalous Azure Operations' analytics rule template in Microsoft Sentinel uses machine learning to baseline Azure subscription activity and flag unusual operations, which directly matches the hunter's goal of detecting anomalous Azure activity. It is purpose-built for Azure control-plane events.

Exam trap

The trap is confusing sign-in anomaly detection (identity layer) with Azure operations anomaly detection (control-plane layer) — both are ML rules but target different telemetry.

How to eliminate wrong answers

Option A is wrong because 'Anomalous Sign-In Locations' targets Azure AD/Entra ID sign-in geography, not Azure subscription operations. Option C is wrong because 'Anomalous User Behavior' is a UEBA concept rather than a specific Sentinel analytics rule template for Azure operations. Option D is wrong because 'Lateral Movement Detection' is a Fusion/behavioral detection scenario, not an ML anomaly template for Azure subscription activity.

12
Multi-Selecthard

Which THREE indicators are commonly associated with ransomware activity in Microsoft Sentinel threat hunting?

Select 3 answers
A.Network connections to known C2 infrastructure
B.Unusual DNS queries to known safe domains
C.Excessive failed logon attempts from a single IP
D.Mass file rename or extension changes
E.Scheduled task creation on multiple endpoints
AnswersA, D, E

Ransomware communicates with C2 servers for key exchange.

Why this answer

Ransomware activity commonly involves three indicators: network connections to known C2 infrastructure (command and control communication), mass file rename or extension changes (file encryption), and scheduled task creation on multiple endpoints (persistence mechanism). Option A (unusual DNS queries to known safe domains) is not typical for ransomware, and option C (excessive failed logon attempts) is more indicative of brute-force attacks. Therefore, the correct options are A, D, and E.

13
MCQeasy

You need to create a custom detection rule in Microsoft Sentinel that alerts when an anomalous number of failed logons occur from a single IP address within 5 minutes. Which KQL operator should you use to count failed logons per IP?

A.summarize
B.project
C.where
D.extend
AnswerA

The summarize operator aggregates log data, allowing you to count failed logons grouped by IP address within a five-minute bin. This produces the per-IP threshold needed to trigger the anomalous failed-logon alert in Microsoft Sentinel.

Why this answer

'summarize' is used to aggregate counts per key (IP). Option B (project) only selects columns. Option C (where) filters rows.

Option D (extend) adds calculated columns.

14
Multi-Selectmedium

Which TWO of the following are valid methods to perform threat hunting in Microsoft Sentinel? (Choose TWO.)

Select 2 answers
A.Create and save custom KQL queries in the Hunting blade
B.Use the built-in hunting queries in the Microsoft Sentinel Hunting blade
C.Configure automated response rules to detect threats
D.Use Workbooks to visualize data and identify anomalies
E.Create a Playbook to automatically run queries on a schedule
AnswersA, B

Saved custom KQL queries in the Hunting blade let analysts run reusable, scheduled or ad hoc searches across Sentinel's Log Analytics workspace, directly satisfying the requirement for a valid threat-hunting method rather than relying solely on automated analytics rules.

Why this answer

Option A is correct because the Hunting blade in Microsoft Sentinel lets analysts create, save, and run custom KQL (Kusto Query Language) queries against the Log Analytics workspace, which is a core proactive threat-hunting technique. Option B is correct because Microsoft Sentinel ships with built-in hunting queries (based on MITRE ATT&CK tactics) that can be run directly from the Hunting blade to surface suspicious activity. Option C is not a hunting method; automation rules are used to trigger responses (such as running playbooks or changing incident properties) after an alert or incident is created, not to proactively search for threats.

Option D is incorrect because Workbooks are for visualization and reporting of data, not for the query-driven, hypothesis-based exploration that defines threat hunting. Option E is incorrect because Playbooks are Logic Apps-based automation workflows that respond to incidents or alerts, not a mechanism for scheduling ad-hoc hunting queries.

Exam trap

SC-200 often tests whether candidates confuse threat hunting (interactive, query-driven investigation in the Hunting blade) with automated detection and response (Analytics Rules, Automation Rules, and Playbooks).

15
MCQmedium

You are investigating a detection in Microsoft Defender for Endpoint. The PowerShell output shows a threat with ID 2147723152. Which type of threat does this ID represent?

A.Ransomware
B.HackTool
C.Worm
D.Trojan
AnswerB

HackTool is the correct classification because detection ID 2147723152 corresponds to a known hacking utility, which Defender categorizes under the HackTool threat type. These tools are commonly used for privilege escalation, credential dumping, or lateral movement, and their detection is based on file signatures and behavior analytics. The alert's ID directly maps to this family, confirming the verdict.

Why this answer

Threat ID 2147723152 corresponds to a hacktool (specifically, a tool used for penetration testing), often detected as 'HackTool:MSIL/Mimikatz!dha'.

16
MCQmedium

You are using Microsoft Defender for Cloud Apps to hunt for suspicious OAuth app permissions. Which activity type should you look for to detect a potentially malicious app that was granted high privileges by a user?

A.Consent to application
B.Add service principal
C.Update application
D.Add app role assignment grant
AnswerA

Consent to application records the OAuth grant event, capturing the user, the application and the scopes requested. This directly satisfies the stem's requirement to detect a malicious app granted high privileges by a user, since the consent activity surfaces the permission grant itself rather than later API usage.

Why this answer

'Consent to application' (Option A). This activity captures when a user grants OAuth permissions to an application, which is the key indicator of high-privilege app consent. Option B, 'Add service principal', relates to creating a service principal object in Azure AD, not user consent.

Option C, 'Update application', involves modifying an app's configuration, not consent. Option D, 'Add app role assignment grant', is about assigning an app role to a user or group, which is a separate permission grant that does not involve user consent directly.

17
MCQhard

As a threat hunter at Contoso, you are investigating a potential advanced persistent threat (APT) that may have compromised multiple Azure subscriptions. You have Microsoft Defender for Cloud enabled and Microsoft Sentinel collecting data from all subscriptions. You suspect the attacker is using Azure Resource Manager operations to create malicious resources. You need to create a hunting query that identifies anomalous Azure management operations, specifically focusing on operations that create new resources (e.g., virtual machines, storage accounts) from unusual IP addresses or at unusual times. Which approach should you take?

A.Use the CommonSecurityLog table to analyze network traffic from management tools.
B.Use the AzureActivity table in Microsoft Sentinel to query for any operation where the OperationNameValue contains 'write' and then manually review each result.
C.Use the AzureActivity table to filter for operations where HttpMethod == 'PUT' (create/update), then summarize by CallerIpAddress and bin(TimeGenerated, 1h) to find spikes or unusual caller IPs.
D.Query the SigninLogs table in Microsoft Sentinel for all interactive sign-ins to the Azure portal, then cross-reference with Azure Activity logs.
AnswerC

The AzureActivity table records control-plane operations, so filtering on HttpMethod == 'PUT' isolates resource creation and update calls. Summarising by CallerIpAddress with bin(TimeGenerated, 1h) surfaces anomalous IP addresses and off-hours spikes, directly satisfying the requirement to hunt suspicious Azure Resource Manager resource-creation activity.

Why this answer

Azure Resource Manager write operations are logged in the AzureActivity table, and create/update operations use HTTP PUT (or sometimes PATCH). Filtering for HttpMethod == 'PUT' isolates resource-creation activity, and summarizing by CallerIpAddress with a time bin (e.g., 1h) surfaces spikes or unusual source IPs that indicate anomalous management-plane activity. This directly targets the APT's resource-creation behavior from unusual IPs or times.

Exam trap

SC-200 often tests table selection — candidates confuse SigninLogs (authentication) with AzureActivity (control-plane operations) or pick CommonSecurityLog (network logs) when the question is about ARM resource creation.

How to eliminate wrong answers

Option A is wrong because CommonSecurityLog contains network/security appliance logs (firewall, proxy, IDS), not Azure control-plane operations — it cannot show ARM resource creation. Option B is wrong because filtering only on OperationNameValue containing 'write' is too broad and lacks the IP/time summarization needed to identify anomalies; manual review of every write is not a scalable hunting approach. Option D is wrong because SigninLogs captures authentication events, not resource-creation operations; cross-referencing sign-ins with activity logs is useful context but does not by itself identify anomalous ARM write operations from unusual IPs.

18
Multi-Selectmedium

Which TWO data sources are most relevant for threat hunting for lateral movement using remote service creation (e.g., WMI, PsExec)?

Select 2 answers
A.DeviceRegistryEvents
B.DeviceEvents
C.DeviceNetworkEvents
D.DeviceFileEvents
E.DeviceProcessEvents
AnswersC, E

DeviceNetworkEvents captures outbound and inbound connection attempts, including connections to TCP port 445, which is used for SMB file sharing to remote admin shares. Lateral movement techniques such as PsExec generate distinctive network connections to hosts on port 445 or any high-order port, making this telemetry among the most relevant for detecting an attacker pivoting across systems. The source IP, destination IP, and port data directly expose the network-level footprint of a move.

Why this answer

Correct options: C and E. DeviceProcessEvents captures process creation on remote machines (e.g., services.exe, cmd.exe) which is indicative of remote service creation via WMI or PsExec. DeviceNetworkEvents captures outbound network connections to high ports (e.g., 135, 445) on remote machines.

Option A (DeviceRegistryEvents) captures registry modifications, not directly relevant. Option B (DeviceEvents) is less specific for this scenario. Option D (DeviceFileEvents) captures file writes, not process execution.

19
MCQmedium

A threat hunter is using Microsoft Defender for Endpoint advanced hunting to find devices that have a specific file hash associated with a known malware variant. The analyst wants to include devices that have the file in any location, including quarantined items. Which table and column should be used?

A.DeviceImageLoadEvents, SHA256
B.DeviceFileEvents, SHA256
C.DeviceNetworkEvents, RemoteIP
D.DeviceProcessEvents, ProcessCommandLine
AnswerB

DeviceFileEvents records file creation and modification activity with SHA256 hashes, including quarantined items, so filtering on the known hash returns every device that encountered the file regardless of location. This satisfies the requirement to include quarantined detections.

Why this answer

DeviceFileEvents tracks file creation, modification, and deletion events, including those that are quarantined, and it includes the SHA256 column for file hashes. Option A (DeviceImageLoadEvents) is for image (DLL) loads, not general file info. Option C (DeviceNetworkEvents) covers network connections, not files.

Option D (DeviceProcessEvents) involves process execution, not file discovery, and its ProcessCommandLine column does not contain file hashes.

20
MCQmedium

You are a threat hunter at Contoso. You suspect that an attacker is using the 'net user' command to create local accounts on compromised machines. You need to write a KQL query in Microsoft Defender XDR advanced hunting to find all instances of 'net user' being executed. Which operator should you use to search for the command line containing 'net user'?

A.has
B.startswith
C.contains
D.endswith
AnswerC

The contains operator checks for a substring anywhere in the string, so it will match command lines that include 'net user' even if there are additional arguments. This is appropriate for detecting the execution of 'net user' because the command may appear with various parameters. However, be aware that contains is case-insensitive and can be slower than has on large datasets.

Why this answer

To detect the 'net user' command, you need to search for the substring within the command line. The contains operator is designed for this purpose and will match any command line that includes 'net user', regardless of position. Other operators like startswith or endswith are too position-specific and would miss common variations.

Exam trap

The trap here is using has, which searches for whole terms and would not match the phrase 'net user' because it contains a space and is not a single term.

21
MCQeasy

A threat hunter wants to use Microsoft Sentinel to hunt for signs of brute-force attacks against Azure AD (now Microsoft Entra ID). Which data connector should be enabled to ingest sign-in logs?

A.Windows Security Events via AMA
B.DNS (Preview)
C.Microsoft Entra ID Audit Logs
D.Microsoft Entra ID
AnswerD

Microsoft Entra ID is correct because this data connector streams both sign-in logs and audit logs into Microsoft Sentinel via diagnostic settings. The sign-in logs include interactive, non-interactive, service principal, and managed identity sign-ins, with rich details like MFA result, Conditional Access policy, and risk level. This comprehensive authentication telemetry is exactly what a threat hunter needs to detect unusual or malicious cloud sign-in behavior.

Why this answer

Microsoft Entra ID (formerly Azure AD) connector. This connector ingests sign-in logs, which contain authentication attempts and can be used to detect brute-force attacks. Option A (Windows Security Events via AMA) captures on-premises Windows security events, not cloud sign-ins.

Option B (DNS Preview) ingests DNS query logs, not sign-in logs. Option C (Microsoft Entra ID Audit Logs) captures audit logs (e.g., user management, configuration changes), not authentication sign-in logs. Therefore, only Option D provides the necessary sign-in log data for hunting brute-force attacks.

22
MCQhard

Refer to the exhibit. You are using a hunting query in Microsoft Defender XDR to find devices generating excessive DNS queries. The query returns many results, but you want to exclude legitimate DNS servers. What is the best approach to refine the query?

A.Add a `where` clause to exclude known internal DNS server IPs.
B.Join with DeviceInfo to filter by device type.
C.Change the RemotePort filter to UDP 53 only instead of all DNS.
D.Increase the count threshold to 5000.
AnswerA

Excluding known DNS servers reduces noise from legitimate traffic.

Why this answer

Correct answer: A. Adding a `where` clause to exclude known internal DNS server IPs reduces false positives by filtering out legitimate DNS traffic from your own DNS servers, which generate high DNS query volumes by design. Options B, C, and D are incorrect: B – Changing the RemotePort filter to UDP 53 only is already implied in a DNS query hunt and does not exclude internal servers; C – Joining with DeviceInfo may not effectively filter out DNS servers and could add complexity; D – Increasing the threshold risks missing true excessive queries that are still below the new threshold but above normal.

23
Multi-Selecthard

You are building a threat hunting query in Microsoft Sentinel to detect potential lateral movement via Windows Management Instrumentation (WMI). You want to identify processes that were created remotely using WMI, which often indicates an attacker moving laterally. Which two data sources or fields should you use in your query to detect this activity? (Choose two.)

Select 2 answers
A.DeviceEvents with ActionType == 'WmiProcessCreate'
B.DeviceProcessEvents with InitiatingProcessFileName == 'wmiprvse.exe'
C.DeviceRegistryEvents with RegistryKey contains 'WMI'
D.DeviceNetworkEvents with RemotePort == 135
E.DeviceLogonEvents with LogonType == 3
AnswersA, B

DeviceEvents includes various event types, and the ActionType 'WmiProcessCreate' specifically logs process creation via WMI. This is a direct signal of WMI-based process execution, which is exactly what you need to detect lateral movement. Querying DeviceEvents for this action type will surface relevant events without relying on parent process inference.

Why this answer

To detect WMI-based lateral movement, you need process creation events where the parent is wmiprvse.exe (indicating WMI spawned the process) or events explicitly logged as WmiProcessCreate. DeviceProcessEvents with InitiatingProcessFileName 'wmiprvse.exe' and DeviceEvents with ActionType 'WmiProcessCreate' both directly capture this behavior. Other sources like network events or logon events are too generic and do not confirm WMI process execution.

Exam trap

The trap here is assuming that network connections to port 135 or generic network logons are sufficient to detect WMI lateral movement, when only process-level events tied to WMI can confirm remote process creation.

24
MCQhard

Your organization uses Microsoft Sentinel with the Microsoft Defender XDR connector. During a hunt, you notice that some alerts from Microsoft Defender for Identity are not appearing in Sentinel. You have verified the connector is enabled and data is flowing for other Defender products. What is the most likely cause?

A.The Microsoft Sentinel pricing tier is set to Free, which limits data ingestion.
B.The 'IdentityLogonEvents' data type is disabled in the Microsoft Sentinel connector configuration.
C.The Microsoft Sentinel workspace is in a different region than Microsoft Defender for Identity.
D.Your tenant does not have the required Microsoft Entra ID P2 license for Microsoft Defender for Identity alerts.
AnswerD

Microsoft Defender for Identity alerts only flow to Microsoft Sentinel when the tenant has the appropriate license, such as Microsoft Entra ID P2 (or a Microsoft 365 E5 license) that includes the MDI service plan. Without this license, the connector may show a healthy status but will not forward MDI alerts to the SecurityAlert table. This is a well-known licensing prerequisite and the most likely reason for the symptom.

Why this answer

Microsoft Defender for Identity alerts require a premium Azure AD P2 license to be ingested via the connector. Option A is wrong because the connector is enabled. Option B is wrong because data ingestion is working for other products.

Option C is wrong because the data types are not disabled.

25
Multi-Selectmedium

Which TWO Microsoft 365 Defender advanced hunting tables would you use together to investigate a potential data exfiltration via email?

Select 2 answers
A.EmailEvents
B.EmailAttachmentInfo
C.DeviceNetworkEvents
D.CloudAppEvents
E.DeviceProcessEvents
AnswersA, B

The EmailEvents table in Microsoft 365 Defender Advanced Hunting is the primary source for email metadata, including the sender, recipient, subject, and message ID (NetworkMessageId). It also records delivery status (Delivered, Blocked, Failed) and detection verdicts for malware, phishing, and spam. This table is essential for hunting email-borne threats because it allows you to filter by specific senders or recipients, inspect message disposition, and correlate with other email and identity tables.

Why this answer

EmailEvents is correct because it is the advanced hunting table that records email message-level metadata and delivery/security verdicts (sender, recipient, subject, timestamps, delivery action, and threat types), which is essential to identify suspicious outbound messages tied to exfiltration. EmailAttachmentInfo is correct because it provides per-attachment details for those messages (file name, SHA-256 hash, file type, and size), letting you pivot from an EmailEvents record via NetworkMessageId to inspect what data was actually attached and sent. Together they correlate the message context with the payload, which is the core of an email-based exfiltration investigation.

DeviceNetworkEvents, CloudAppEvents, and DeviceProcessEvents are not the right pairing here: they cover endpoint network connections, cloud app/service activity, and process execution respectively, none of which directly expose email message and attachment metadata for an email exfiltration scenario.

Exam trap

The trap is confusing email-layer tables (EmailEvents, EmailAttachmentInfo) with endpoint or cloud-app tables — candidates pick DeviceNetworkEvents or CloudAppEvents because they sound like they cover 'exfiltration' broadly.

26
MCQmedium

You are a threat hunter in Microsoft Sentinel. You suspect an attacker is using the Windows utility certutil.exe to download malicious payloads from an external URL. You want to write a hunting query that detects command lines where certutil.exe is used with the -urlcache or -verifyctl arguments. Which KQL query should you use?

A.DeviceNetworkEvents | where InitiatingProcessFileName == "certutil.exe" | where RemoteUrl contains "http"
B.DeviceEvents | where ActionType == "CertUtilDownload" | where AdditionalFields contains "urlcache"
C.DeviceFileEvents | where FileName == "certutil.exe" | where FolderPath contains "urlcache"
D.DeviceProcessEvents | where FileName == "certutil.exe" | where ProcessCommandLine has_any ("-urlcache", "-verifyctl")
AnswerD

This query correctly targets the DeviceProcessEvents table in Microsoft Defender XDR advanced hunting, filters for the process name certutil.exe, and uses has_any to match either of the suspicious arguments. Because DeviceProcessEvents captures process creation events with full command lines, it is the appropriate table for detecting this behavior. The has_any operator efficiently checks for multiple substrings in the command line, making it ideal for this scenario.

Why this answer

The correct query uses DeviceProcessEvents to capture process creation events and filters for certutil.exe with the suspicious arguments -urlcache or -verifyctl. This directly matches the hunting hypothesis. Other tables either lack command-line data or use incorrect fields.

DeviceProcessEvents is the authoritative source for process command lines in Microsoft Defender XDR, making it the right choice for detecting this living-off-the-land binary abuse.

Exam trap

The trap here is assuming that network or file events will reveal command-line arguments, when only process creation events capture the full command line used to launch a binary.

27
MCQeasy

Your team is conducting a threat hunt for data exfiltration using Microsoft Defender for Cloud Apps. Which activity is most suspicious and should be included in the hunting query?

A.A user viewing files in OneDrive for Business.
B.A user downloading a single file from SharePoint Online.
C.A user sharing a file with an internal colleague.
D.A user downloading hundreds of files from SharePoint Online in a short time.
AnswerD

Downloading hundreds of files from SharePoint Online in a short period matches mass-download behaviour that Defender for Cloud Apps flags as potential exfiltration. The volume and compressed timeframe satisfy the suspicious-activity constraint in the stem, unlike routine single-file access, making it the strongest hunting query candidate.

Why this answer

Mass download of hundreds of files from SharePoint Online in a short time is a classic indicator of data exfiltration. Option D is correct. Option A is incorrect because viewing files is normal user activity and not indicative of exfiltration.

Option B is incorrect because downloading a single file is routine and not suspicious. Option C is incorrect because sharing a file with an internal colleague is typical collaboration and less likely to be exfiltration than mass downloads or external sharing.

28
Multi-Selecthard

Which THREE are essential components of a threat hunting hypothesis in Microsoft Sentinel? (Choose three.)

Select 3 answers
A.Adversary goal or objective
B.Alert severity level
C.Data sources to query
D.Automated response plan
E.Expected indicators of compromise (IOCs)
AnswersA, C, E

A hypothesis must state what the adversary is trying to achieve, since the goal directs which behaviours, telemetry and queries the hunter pursues. Without an objective, hunting lacks a testable premise and becomes unfocused data review.

Why this answer

A threat hunting hypothesis in Microsoft Sentinel must be structured around what the adversary is trying to achieve, so option A (Adversary goal or objective) is correct because it defines the behavior or intent being tested, such as credential theft or lateral movement, which guides the entire hunt. Option C (Data sources to query) is correct because a hypothesis is only actionable if it maps to concrete telemetry in Sentinel, such as SecurityEvent, Syslog, SigninLogs, or OfficeActivity tables queried via KQL, so the hunter knows where to look. Option E (Expected indicators of compromise (IOCs)) is correct because the hypothesis must specify the observable artifacts that would confirm or refute it, such as specific process names, IP addresses, hashes, or anomalous sign-in patterns, enabling validation of the hunt.

Option B (Alert severity level) is not essential because severity is a triage attribute of analytics rules and incidents, not a defining element of a hunting hypothesis. Option D (Automated response plan) is not essential because automation and playbooks belong to incident response and SOAR workflows, whereas threat hunting is an investigative, hypothesis-driven activity that may not trigger automated actions.

Exam trap

SC-200 often tests whether candidates can separate the hunting hypothesis (goal, data, expected evidence) from detection and response artifacts (severity, playbooks) — the distractor options sound relevant to security operations but are not part of the hypothesis construct.

29
MCQmedium

A threat hunter is investigating a potential compromise involving a user account that has been used to sign in from multiple locations within a short time. The hunter wants to use Microsoft Sentinel to find all sign-in events for that user from different IP addresses in the last 24 hours. Which KQL query should be used?

A.SigninLogs | where TimeGenerated > ago(24h) | where UserPrincipalName == "user@domain.com" | summarize count() by IPAddress
B.SecurityEvent | where TimeGenerated > ago(24h) | where TargetUserName == "user@domain.com" | summarize count() by IpAddress
C.AuditLogs | where TimeGenerated > ago(24h) | where InitiatedBy.user.userPrincipalName == "user@domain.com" | summarize count() by IPAddress
D.CommonSecurityLog | where TimeGenerated > ago(24h) | where SourceUserID == "user@domain.com" | summarize count() by SourceIP
AnswerA

SigninLogs holds Microsoft Entra ID interactive sign-in events with UserPrincipalName and IPAddress, so filtering the last 24 hours and summarising by IPAddress satisfies the requirement to enumerate distinct source addresses for that user. AADNonInteractiveUserSignInLogs would not match interactive portal sign-ins.

Why this answer

The SigninLogs table in Microsoft Sentinel stores Azure AD (Entra ID) interactive and non-interactive sign-in events, including the UserPrincipalName and IPAddress fields needed to trace a user's authentication activity across locations. Querying SigninLogs with a 24-hour time filter, matching on UserPrincipalName, and summarizing by IPAddress directly answers the hunter's question about which IPs the account signed in from. This is the canonical table for identity-based sign-in hunting in Sentinel.

Exam trap

SC-200 often tests whether candidates know which Sentinel table holds which telemetry type — specifically confusing Azure AD sign-in data (SigninLogs) with audit activity (AuditLogs) or on-prem Windows logons (SecurityEvent).

How to eliminate wrong answers

Option B is wrong because SecurityEvent holds Windows Security event log data (e.g., 4624/4625) from onboarded machines or the Log Analytics agent, not Azure AD sign-in telemetry, and TargetUserName/IpAddress refer to local or domain logon events rather than cloud identity sign-ins. Option C is wrong because AuditLogs contains Azure AD audit/activity events (like role changes or app consent) via the InitiatedBy property, not sign-in records, so it would miss authentication events entirely. Option D is wrong because CommonSecurityLog ingests CEF-formatted logs from third-party security appliances (firewalls, proxies, IDS), and SourceUserID/SourceIP reflect those devices' events, not Azure AD sign-in data.

30
MCQeasy

While threat hunting in Microsoft Defender for Cloud Apps, you notice a user has an unusually high number of failed login attempts from a single IP address. What is the most effective next step to determine if this is a brute-force attack?

A.Immediately block the IP address
B.Investigate the IP address in the Microsoft Defender for Cloud Apps Activity log to review all failed attempts
C.Create a new anomaly detection policy for that user
D.Check the user's device for malware
AnswerB

Reviewing all failed attempts from that IP in the Activity log reveals the pattern, volume and targeted accounts, confirming whether the behaviour constitutes brute-force credential guessing rather than isolated user error. This evidence-based correlation is the most effective next investigative step.

Why this answer

The most direct method is to investigate the IP address in the Microsoft Defender for Cloud Apps Activity log by filtering for that IP and reviewing the failed attempts. Option A (Immediately block the IP) is premature without confirming the pattern. Option C (Creating an anomaly detection policy) is for future detection, not for immediate analysis.

Option D (Checking the user's device for malware) is not relevant for cloud app access failures.

31
MCQmedium

You are investigating a potential ransomware incident in Microsoft Defender XDR. You need to identify files that have been modified with a known ransomware extension across all devices. Which advanced hunting operator should you use to search for file names ending with '.locked' in the DeviceFileEvents table?

A.endswith
B.contains
C.matches regex
D.startswith
AnswerA

The endswith operator checks if a string ends with a specified suffix. Using endswith '.locked' on the FileName column will accurately identify files that have been renamed with the '.locked' extension, which is characteristic of ransomware encryption. This operator is case-insensitive and efficient for this purpose.

Why this answer

To find files with a specific extension, you need to match the end of the file name. The endswith operator is designed for this purpose and will correctly identify files ending with '.locked'. Using contains might match unintended substrings, and startswith would look at the wrong end of the string.

Exam trap

The trap here is using contains instead of endswith, which can lead to false positives by matching the substring anywhere in the file name.

32
MCQeasy

A threat hunter is investigating a potential data exfiltration via DNS tunneling. Which Microsoft Defender XDR advanced hunting table should the analyst primarily use to examine DNS queries from endpoints?

A.DeviceEvents
B.IdentityLogonEvents
C.AlertInfo
D.EmailEvents
AnswerA

DeviceNetworkEvents records network connection events from onboarded endpoints, including DNS query details and remote addresses. This makes it the primary table for spotting DNS tunnelling patterns such as high-volume or encoded queries to suspicious domains.

Why this answer

In Microsoft Defender XDR advanced hunting, raw DNS query telemetry from endpoints is recorded in the DeviceEvents table, where events with ActionType equal to 'DnsQuery' include the queried domain (in AdditionalFields) and the initiating process. DeviceNetworkEvents records network connection events (RemoteIP, RemoteUrl, RemotePort, etc.) and does not contain a DnsQuery field or per-query DNS resolution data. Therefore, to examine DNS queries from endpoints for suspected DNS tunneling, the analyst should use DeviceEvents filtered on ActionType == 'DnsQuery'.

Exam trap

The trap is assuming that any table with 'Network' in the name contains DNS data, or defaulting to AlertInfo because the scenario mentions an investigation. The exam tests whether you know that raw endpoint DNS query telemetry lives in DeviceEvents (ActionType == 'DnsQuery'), not DeviceNetworkEvents.

How to eliminate wrong answers

Option B is wrong because IdentityLogonEvents contains authentication events (logons, failed logons, credential usage) from identity providers — it has no DNS query data. Option C is wrong because AlertInfo stores metadata about generated alerts (title, severity, category), not raw DNS telemetry; it tells you an alert fired, not what DNS queries occurred. Option D is wrong because EmailEvents covers email message flow and delivery metadata (sender, recipient, attachments, URLs), which is relevant to phishing investigations but contains no endpoint DNS query records.

33
MCQeasy

A threat hunter wants to use Microsoft Sentinel's UEBA to identify anomalous behavior. Which data connector must be enabled to provide the necessary Azure Active Directory (now Microsoft Entra ID) sign-in logs for UEBA?

A.Office 365
B.Microsoft Entra ID Audit
C.Microsoft Entra ID
D.Windows Security Events via AMA
AnswerC

The Microsoft Entra ID data connector ingests sign-in and audit logs into Microsoft Sentinel, supplying the identity events UEBA analyses for anomalous behaviour detection. Enabling it is required before UEBA can surface risky sign-in activity.

Why this answer

UEBA in Microsoft Sentinel requires sign-in logs to detect anomalous behavior. The Microsoft Entra ID connector (option C) provides these sign-in logs from Azure AD/Entra ID. Option A (Office 365) provides Exchange, Teams, and SharePoint logs, but not sign-in logs.

Option B (Microsoft Entra ID Audit) provides only audit logs, not sign-in events. Option D (Windows Security Events via AMA) provides security event logs from Windows machines, which do not contain cloud sign-in data. Therefore, the Microsoft Entra ID connector is the correct choice.

34
Multi-Selecthard

Which THREE of the following are recommended practices for creating effective threat hunting queries in Microsoft Sentinel? (Select three.)

Select 3 answers
A.Use only broad patterns to avoid missing anything
B.Use wildcards extensively to capture variations
C.Include known indicators of compromise from threat feeds
D.Map queries to MITRE ATT&CK techniques
E.Limit the query to a specific time range
AnswersC, D, E

Incorporating threat-feed indicators of compromise lets queries match observed malicious artefacts—IP addresses, domains, file hashes—against telemetry already ingested in Microsoft Sentinel, satisfying the stem's requirement for effective hunting queries. This converts external threat intelligence into concrete detection logic, surfacing known adversary infrastructure without waiting for an alert to fire.

Why this answer

Option C is correct because incorporating known indicators of compromise (IOCs) such as malicious IP addresses, domains, file hashes, and URLs from threat intelligence feeds lets hunting queries directly surface activity tied to known adversaries, which is a core recommended practice in Microsoft Sentinel. Option D is correct because mapping queries to MITRE ATT&CK techniques aligns hunting with specific adversary tactics and techniques, enabling coverage tracking, prioritization of gaps, and consistent query design across the kill chain. Option E is correct because constraining a query to a specific, relevant time range improves performance and reduces noise, ensuring the hunt focuses on the window of interest rather than scanning the entire retention period.

Option A is not recommended because overly broad patterns generate excessive false positives and dilute the signal, and Option B is not recommended because excessive wildcard use degrades KQL query performance and precision, making results harder to triage.

35
MCQmedium

You are threat hunting in Microsoft Defender for Cloud Apps. You want to identify users who have enabled mailbox forwarding rules to external domains, which could indicate data exfiltration. Which log source should you query?

A.Office 365 audit logs
B.Microsoft Entra ID sign-in logs
C.Windows Event logs from domain controllers
D.Azure Network Watcher logs
AnswerA

Office 365 audit logs capture Exchange mailbox rule creation and modification events, including Set-InboxRule operations that forward mail externally. Querying this source in Microsoft Sentinel surfaces users who configured external forwarding, matching the exfiltration hunt.

Why this answer

Microsoft Defender for Cloud Apps can ingest Office 365 audit logs, which include Exchange mailbox audit events for forwarding rules. Options B, C, and D are incorrect: Microsoft Entra ID sign-in logs (B) do not contain mailbox forwarding events, Windows Event logs from domain controllers (C) are device-focused and do not include Exchange mailbox rules, and Azure Network Watcher logs (D) are for network monitoring and do not include mailbox rules.

36
MCQmedium

Your security team uses Microsoft Sentinel to hunt for signs of credential theft. They want to correlate Azure AD sign-in logs with Microsoft Defender for Cloud Apps alerts. Which KQL operator should they use to join the two tables on the user principal name?

A.union
B.join
C.lookup
D.evaluate
AnswerB

join is correct because the KQL join operator correlates rows from two tabular expressions on one or more equality conditions (keys), returning rows that contain columns from both sides. For example, joining SigninLogs with AADAuditLogs on UserId or IP address lets you see a logon event and the subsequent activity side by side, which is exactly the kind of key-based matching needed when hunting across heterogeneous data sources. You can control the output with join kinds such as innerunique, inner, leftouter, and rightouter to tailor the hunt to your hypothesis.

Why this answer

The 'join' operator merges rows from two tables based on a matching key. Option A is incorrect because 'union' appends rows, not correlates. Option C is incorrect because 'lookup' is a type of join but is less common for this scenario.

Option D is incorrect because 'evaluate' is used for plugin execution, not joining tables.

37
Multi-Selecteasy

Which TWO KQL operators are commonly used in threat hunting to join tables based on a key?

Select 2 answers
A.lookup
B.join
C.extend
D.summarize
E.union
AnswersA, B

The lookup operator enriches a fact table by pulling values from a dimension-style table based on equality of specified keys, using left-outer semantics that preserve the left side's row count and only add columns. This is essential in threat hunting for attaching authoritative context—such as user names, asset owners, or threat-intel tags—to raw events without the risk of row multiplication. Unlike join, lookup is optimized for dimension-style, one-to-many enrichment and is a common choice when the goal is to decorate events with descriptive attributes.

Why this answer

Option A, lookup, is correct because it enriches events by joining a fact table with a dimension table on a matching key column, returning only the columns from the lookup table and is optimized for this common threat-hunting enrichment pattern. Option B, join, is correct because it combines rows from two tables based on matching values of a specified key column (e.g., join kind=inner on Account), which is the general-purpose operator for correlating tables in KQL. Option C, extend, is not a join operator; it adds or computes new columns on a single table.

Option D, summarize, aggregates rows into groups using functions like count() or dcount(), not a key-based table join. Option E, union, appends rows from multiple tables into one result set without matching on a key.

Exam trap

SC-200 often tests the distinction between operators that combine tables (join, lookup, union) versus those that transform a single table (extend, summarize), and candidates may mistakenly select `union` for key-based joins.

38
MCQhard

Refer to the exhibit. You are analyzing a potential C2 communication pattern. The KQL query returns no results despite known malicious IPs being active. What is the most likely cause?

A.The query is missing a filter for Direction equal to 'Outbound'.
B.The devices generating the events are not onboarded to Microsoft Defender for Endpoint.
C.The query does not include a filter for ActionType equal to 'ConnectionSuccess'.
D.The RemoteIP field should be replaced with DestinationIpAddress.
AnswerB

Microsoft Defender for Endpoint supplies the device telemetry that Sentinel's advanced hunting and C2-related tables query. Without onboarding, those devices emit no events, so the KQL query returns nothing despite the malicious IPs being active.

Why this answer

If the devices generating the network events are not onboarded to Microsoft Defender for Endpoint, they will not produce any DeviceNetworkEvents, resulting in no query results even when malicious IPs are active. Option A is incorrect because the query does not need a Direction filter to return results; it may include both inbound and outbound by default. Option C is incorrect because filtering on ActionType is not necessary to see the connection events; the absence of a filter does not cause empty results.

Option D is incorrect because RemoteIP is the correct field for the destination IP address in DeviceNetworkEvents; replacing it with DestinationIpAddress would not fix the missing data issue.

39
MCQhard

During a threat hunt, an analyst discovers that a user's device has been sending large amounts of data to an external IP address associated with a known C2 server. The analyst wants to trace the process responsible for the outbound connections. Which Microsoft Defender for Endpoint advanced hunting table should be queried to find the process that initiated the network connections?

A.DeviceProcessEvents
B.DeviceFileEvents
C.DeviceNetworkEvents
D.DeviceEvents
AnswerC

DeviceNetworkEvents is the Advanced Hunting table designed to capture network connection attempts, including local/remote IPs, ports, protocol, and connection state. Critically, it includes the initiating process information (InitiatingProcessId, InitiatingProcessFileName, InitiatingProcessCommandLine), so you can directly attribute the outbound connection to the user's dev process. This makes it the correct choice when the analyst needs the process responsible for an outbound connection.

Why this answer

DeviceNetworkEvents in Microsoft Defender for Endpoint advanced hunting contains network connection events, including the initiating process, remote IP, port, and protocol. To trace which process initiated outbound connections to a known C2 IP, the analyst must query DeviceNetworkEvents, which correlates network activity with the responsible process. This table is purpose-built for network connection telemetry.

Exam trap

SC-200 often tests the distinction between process, file, network, and generic event tables, so candidates must know exactly which table holds network connection telemetry with process attribution.

How to eliminate wrong answers

Option A is wrong because DeviceProcessEvents records process creation, termination, and command-line details, but not network connections, so it cannot directly show which process sent data to an external IP. Option B is wrong because DeviceFileEvents captures file creation, modification, and deletion activity, not network traffic. Option D is wrong because DeviceEvents is a general-purpose table for miscellaneous events like registry changes, logon events, and script execution, not specifically network connection initiations.

40
MCQhard

A threat hunter is using Microsoft Sentinel to hunt for a potential advanced persistent threat (APT) that is using living-off-the-land binaries (LOLBins). The hunter creates a KQL query that lists all instances of certutil.exe making network connections. The query returns many legitimate results. What is the best way to reduce false positives while still detecting malicious use?

A.Replace the query with a Sysmon Event ID 3 (network connect) filter for certutil.exe
B.Remove certutil.exe from the hunting query and focus on other binaries
C.Expand the query to include all LOLBins that make network connections
D.Add additional filters to the query to detect only certutil.exe processes with suspicious command-line arguments (e.g., '-urlcache' or '-split')
AnswerD

Adding filters that match suspicious certutil command-line patterns—such as '-urlcache', '-split', or '-decode'—directly targets the known malicious usage of this tool while ignoring routine certificate work like CRL checks and certificate store queries. In KQL, you would combine the process image with a condition on the command line, for example: where ProcessCommandLine contains "certutil" and (ProcessCommandLine contains "-urlcache" or ProcessCommandLine contains "-split"), to isolate the payload-download behavior. This is far more precise because legitimate administrators rarely invoke certutil with these file-handling switches, especially in conjunction with a remote URL, so the false-positive rate drops dramatically while detection fidelity remains high.

Why this answer

Malicious use of certutil.exe as a LOLBin often involves specific command-line arguments such as '-urlcache' or '-split' to download or encode data. By adding these filters to the KQL query, the hunter can reduce false positives from legitimate certutil.exe network connections while still capturing suspicious activity. Option A (Sysmon Event ID 3) still returns all network connections and does not filter on arguments, so it does not reduce false positives.

Option B would miss potential threats. Option C expands the query to include all LOLBins, which increases noise and does not target the specific binary in question.

41
MCQmedium

During a threat hunt, an analyst discovers a PowerShell script that was executed on multiple servers in the environment. The script connects to an external IP address and downloads a payload. The analyst wants to find all other servers that may have been compromised by the same script. What is the most efficient way to search for this across the environment?

A.Use Sysmon Event ID 1 (process creation) to find PowerShell executions
B.Review the network logs from the firewall for connections to the external IP
C.Use the DeviceProcessEvents table in Microsoft Defender for Endpoint advanced hunting to search for the script's SHA256 hash or command line pattern
D.Query the Windows Event Log for Event ID 4104 (PowerShell script block logging) on each server
AnswerC

The DeviceProcessEvents table records process creation events, including command lines and file hashes, across all onboarded devices. Searching by the script's SHA256 hash or command-line pattern identifies every server where the same PowerShell execution occurred, directly satisfying the requirement to find other compromised servers efficiently.

Why this answer

It leverages Microsoft Defender for Endpoint's advanced hunting to centrally search for the script's SHA256 hash or command line pattern across all endpoints. Option A is incorrect because Sysmon may not be installed on all servers, and querying each server individually is inefficient. Option B is incorrect because network logs only show network connections and do not provide process execution details.

Option D is incorrect because querying Event ID 4104 requires enabling PowerShell script block logging and accessing each server individually, which is less efficient than centralized hunting.

42
MCQeasy

You are a threat hunter using Microsoft Defender XDR. You want to identify all devices that have communicated with a known malicious IP address 203.0.113.10 in the last 30 days. Which Advanced Hunting query should you run?

A.DeviceFileEvents | where RemoteIP == "203.0.113.10" and Timestamp > ago(30d)
B.DeviceEvents | where RemoteIP == "203.0.113.10" and Timestamp > ago(30d)
C.DeviceLogonEvents | where RemoteIP == "203.0.113.10" and Timestamp > ago(30d)
D.DeviceNetworkEvents | where RemoteIP == "203.0.113.10" and Timestamp > ago(30d)
AnswerD

DeviceNetworkEvents contains network connection events from devices, including the remote IP address. Filtering by RemoteIP equal to the malicious IP and a timestamp within the last 30 days will return all devices that communicated with that IP. This is the correct table and fields for this purpose. The Timestamp field is used for time filtering in Advanced Hunting, and the query is straightforward and effective.

Why this answer

DeviceNetworkEvents is the correct Advanced Hunting table for network connection data. It includes fields such as RemoteIP, RemotePort, and LocalIP. By filtering for the specific malicious IP address and limiting to the last 30 days using Timestamp > ago(30d), you can retrieve all devices that communicated with that IP.

This query provides the necessary visibility for threat hunting network-based indicators.

Exam trap

The trap here is selecting tables based on the presence of an IP field without verifying that the table actually records network communications; only DeviceNetworkEvents captures general network connections.

43
MCQeasy

During a threat hunt, you want to identify processes that have made network connections to known malicious IP addresses. Which data source in Microsoft Defender for Endpoint would provide the necessary information?

A.DeviceFileEvents
B.DeviceNetworkEvents
C.DeviceProcessEvents
D.DeviceRegistryEvents
AnswerB

DeviceNetworkEvents records outbound and inbound connection attempts per device, including remote IP addresses, ports and the initiating process. Correlating these events against threat intelligence identifies processes connecting to known malicious IPs, satisfying the hunt requirement.

Why this answer

DeviceNetworkEvents logs network connections including destination IP addresses, which is needed for this threat hunt. Option A is wrong because DeviceFileEvents logs file operations, not network connections. Option C is wrong because DeviceProcessEvents logs process creation, not network connections.

Option D is wrong because DeviceRegistryEvents logs registry changes, not network connections.

44
MCQeasy

To hunt for malicious PowerShell encoded commands, which columns in the DeviceProcessEvents table in Microsoft 365 Defender advanced hunting should you focus on?

A.DeviceName
B.FileName
C.ProcessCommandLine
D.InitiatingProcessFileName
AnswerC

ProcessCommandLine contains the full command line, including the -EncodedCommand parameter and the base64 string attackers use to hide their payload. This is the primary field to inspect when hunting for obfuscated PowerShell, as the encoded blob is present verbatim. In Microsoft 365 Defender's DeviceProcessEvents, this field enables decoding and further analysis, making it the directly relevant column.

Why this answer

Encoded PowerShell commands (e.g., -EncodedCommand or -enc) appear in the full command line used to launch the process, which is captured in the ProcessCommandLine column of DeviceProcessEvents. Filtering or searching ProcessCommandLine for base64-like strings or the -enc switch is the standard hunting technique for detecting obfuscated PowerShell execution.

Exam trap

SC-200 often tests whether candidates know which column holds the actual command-line arguments — candidates pick FileName or InitiatingProcessFileName because they sound process-related, missing that ProcessCommandLine is where encoded payloads live.

How to eliminate wrong answers

Option A is wrong because DeviceName only identifies the host — it tells you where the process ran, not what command was executed, so it cannot reveal encoded PowerShell. Option B is wrong because FileName shows the executable name (e.g., powershell.exe), which is useful for scoping but does not contain the encoded payload. Option D is wrong because InitiatingProcessFileName identifies the parent process (e.g., winword.exe spawning powershell.exe), which is a useful correlation signal but not where the encoded command string lives.

45
MCQmedium

A threat hunter runs the KQL query above in Microsoft Sentinel. What is the main limitation of this query?

A.The query relies on an external data source that may be slow or unavailable
B.The IdentityLogonEvents table does not have an IPAddress column
C.The let statement is incorrectly defined because it uses externaldata without a schema
D.The with(format="csv") is invalid
AnswerA

The query calls an external data source, so its reliability and latency depend on that service rather than Microsoft Sentinel's own log store. If the source is unavailable or slow, the hunt returns incomplete or delayed results, unlike queries against native workspace tables.

Why this answer

The query uses the externaldata() operator to fetch a list of IP addresses from an external URL. This introduces a dependency on that external source, which may be slow, fail, or be out of date. Option A correctly identifies this limitation.

Option B is incorrect because the IdentityLogonEvents table does have an IPAddress column. Option C is incorrect because the let statement is correctly defined with a schema. Option D is incorrect because the with(format='csv') is valid for CSV files.

46
Multi-Selectmedium

Which TWO data sources are most useful for detecting unauthorized lateral movement in a hybrid environment using Microsoft Sentinel?

Select 2 answers
A.Azure Activity Log
B.Network Security Group Flow Logs
C.Microsoft Defender for Endpoint DeviceLogonEvents
D.Windows Security Events (Event ID 4624)
E.Office 365 Audit Logs
AnswersC, D

Defender for Endpoint's DeviceLogonEvents table captures endpoint-level authenticated logon telemetry, including both successful and failed attempts, along with key contextual fields such as logon type, source IP, and the executing process. This makes it invaluable for detecting lateral movement, because it exposes patterns like a single account authenticating to many devices in a short time or unusual logon types (e.g., network logons) that indicate credential reuse. As a native hunting table in Microsoft 365 Defender, it enables queries that directly correlate logon activity with endpoint alerts and device risk indicators.

Why this answer

Option C, Microsoft Defender for Endpoint DeviceLogonEvents, is correct because it records interactive, network, and remote logon attempts (including type 3 and type 10) on endpoints, which are the primary telemetry for spotting credential-based lateral movement across hosts in a hybrid estate. Option D, Windows Security Events (Event ID 4624), is correct because successful logon events on domain-joined servers and workstations reveal authentication across the environment, and analyzing 4624 logon types (e.g., 3 network, 10 RDP) alongside source workstation and account fields exposes lateral movement paths. Option A, Azure Activity Log, is not the best fit because it captures control-plane operations on Azure resources (resource writes, role assignments) rather than host-to-host authentication activity.

Option B, Network Security Group Flow Logs, only shows allowed/denied IP flows at the NSG level and lacks user or process context needed to confirm unauthorized lateral movement. Option E, Office 365 Audit Logs, covers cloud service activities such as mailbox and SharePoint access, not internal endpoint or domain logon traffic.

Exam trap

SC-200 often tests the confusion between network-layer telemetry (NSG Flow Logs) and identity-layer telemetry, tempting candidates to pick flow logs when the question asks about credential-based lateral movement.

47
Multi-Selecthard

Which THREE data sources can be used in Microsoft Sentinel for threat hunting to detect unusual authentication patterns? (Choose three.)

Select 3 answers
A.SecurityEvent (Windows Event Logs)
B.AADNonInteractiveUserSignInLogs
C.CommonSecurityLog
D.OfficeActivity (Office 365)
E.SigninLogs (Microsoft Entra ID)
AnswersA, B, E

SecurityEvent carries Windows logon events, including 4624, 4625 and 4648, exposing failed logons, explicit credential use and unusual logon types. These fields let hunters detect anomalous authentication patterns across on-premises and domain-joined systems forwarded to Microsoft Sentinel.

Why this answer

Option A, SecurityEvent (Windows Event Logs), is correct because it ingests Windows security events such as 4624, 4625, and 4648, which reveal logon successes, failures, and explicit credential use that are essential for spotting unusual authentication patterns on hosts. Option B, AADNonInteractiveUserSignInLogs, is correct because it captures non-interactive Microsoft Entra ID sign-ins (token, service principal, and client-credential flows) that often indicate anomalous or automated authentication activity missed by interactive-only logs. Option E, SigninLogs (Microsoft Entra ID), is correct because it records interactive Entra ID sign-in events with details like IP address, location, device, conditional access result, and risk level, directly supporting detection of unusual authentication behavior.

Option C, CommonSecurityLog, is not among the marked answers because it primarily carries CEF-formatted data from third-party security appliances (firewalls, proxies, IDS/IPS) rather than identity authentication telemetry. Option D, OfficeActivity (Office 365), is not among the marked answers because it focuses on Office 365 workload operations such as file, mailbox, and admin activities, not core authentication sign-in patterns.

Exam trap

SC-200 often tests whether candidates can distinguish identity authentication tables (SigninLogs, AADNonInteractiveUserSignInLogs, SecurityEvent) from activity and network tables (OfficeActivity, CommonSecurityLog), so the trap is selecting OfficeActivity or CommonSecurityLog because they sound security-relevant when the question specifically asks about authentication patterns.

48
MCQhard

You are hunting for signs of ransomware using Microsoft Defender XDR's advanced hunting. Which query pattern would best identify a process that encrypts many files in a short time?

A.DeviceFileEvents | summarize Duration = max(Timestamp)-min(Timestamp) by DeviceName, InitiatingProcessFileName | where Duration < 1h
B.DeviceFileEvents | where ActionType == 'FileModified' | summarize Count = count() by DeviceName, InitiatingProcessFileName, bin(Timestamp, 5m) | where Count > 100
C.DeviceProcessEvents | where FileName in ('powershell.exe', 'wscript.exe') | summarize by DeviceName
D.DeviceFileEvents | summarize Count = count() by DeviceName | where Count > 1000
AnswerB

Aggregating DeviceFileEvents by device, initiating process and five-minute bins, then filtering counts above 100, directly surfaces mass file modification — the ransomware encryption signature. Grouping by InitiatingProcessFileName attributes the burst to a specific process, satisfying the stem's requirement to identify rapid, high-volume encryption activity.

Why this answer

It counts the number of file modifications per initiating process per 5-minute window using DeviceFileEvents, and then filters for those with more than 100 modifications. This directly detects a process that is rapidly encrypting many files, which is a strong indicator of ransomware. Option A is wrong because it measures the duration between the first and last file event by a process, not the count; a process could encrypt files over a longer period and still be suspicious, but this query would miss high-density encryption in a short burst.

Option C is wrong because it only looks at process creation events for specific script interpreters (powershell.exe, wscript.exe), not at file modifications, and it fails to identify encryption activity from other executables. Option D is wrong because it counts all file events per device without grouping by process, so it cannot pinpoint which process is responsible for the encryption.

49
Multi-Selecthard

Which THREE of the following are indicators of a potential pass-the-hash attack that a threat hunter should investigate in Microsoft Defender for Identity?

Select 3 answers
A.High volume of TGS requests from a single user
B.Multiple failed logon attempts followed by a successful logon from the same IP
C.Anomalous NTLM authentication from a domain controller
D.Event ID 4624 with LogonType 9 (NewCredentials) from a non-privileged account
E.Anomalous spike in CPU usage on domain controllers
AnswersB, C, D

A burst of failed logons immediately followed by a success from the same IP signals credential brute-forcing or hash reuse, matching the pass-the-hash pattern where stolen NTLM hashes authenticate without knowing the plaintext password. Defender for Identity surfaces this sequence as suspicious authentication behaviour worth hunting.

Why this answer

Option B is correct because a burst of failed logons immediately followed by a success from the same source IP is a classic credential-stuffing/brute-force precursor that often precedes or accompanies pass-the-hash, where stolen NTLM hashes are replayed to authenticate. Option C is correct because pass-the-hash relies on NTLM authentication, and anomalous NTLM traffic originating from a domain controller (which should normally use Kerberos for domain auth) is a strong Defender for Identity signal of hash replay or lateral movement. Option D is correct because LogonType 9 (NewCredentials) with Event ID 4624 indicates a process is using explicit alternate credentials via NTLM, which is exactly how tools like Mimikatz or PsExec execute pass-the-hash with a stolen hash rather than a password.

Option A is not correct because a high volume of TGS requests points to Kerberoasting or ticket-based attacks, not pass-the-hash, which uses NTLM rather than TGS tickets. Option E is not correct because CPU spikes on domain controllers are a generic performance/availability indicator and are not a specific behavioral signature of pass-the-hash in Defender for Identity.

50
Multi-Selectmedium

Which TWO tables in Microsoft Defender XDR advanced hunting provide information about user authentication events?

Select 2 answers
A.AlertInfo
B.AADSignInEventsBeta
C.EmailEvents
D.IdentityLogonEvents
E.DeviceNetworkEvents
AnswersB, D

AADSignInEventsBeta records Microsoft Entra ID sign-in events, capturing interactive and non-interactive authentication attempts with user, application, device and conditional access details. This directly satisfies the stem's requirement for user authentication data, complementing IdentityLogonEvents, which covers on-premises Active Directory authentication rather than cloud sign-ins.

Why this answer

Option B (AADSignInEventsBeta) is correct because this table in Microsoft Defender XDR advanced hunting contains Microsoft Entra ID (Azure AD) sign-in events, including interactive and non-interactive user authentication activity such as successful and failed sign-ins. Option D (IdentityLogonEvents) is correct because it records authentication events across on-premises identity services, including Active Directory and other identity providers surfaced through Defender for Identity, capturing logon and authentication activity for user accounts. Option A (AlertInfo) is not correct because it stores metadata about generated alerts rather than raw authentication events.

Option C (EmailEvents) is not correct because it holds email message and delivery information, not user sign-in data. Option E (DeviceNetworkEvents) is not correct because it contains network connection events from devices, not user authentication records.

51
MCQhard

A threat hunter is using Microsoft Sentinel and Microsoft Defender XDR to hunt for a potential cross-domain attack where an attacker compromised an on-premises server and then used a privileged account to sign into Microsoft 365 from a new IP. The hunter wants to identify the server using a query that combines Windows Event Logs from the server with Microsoft 365 sign-in logs. Which approach should the hunter take to correlate the data?

A.Create a Sentinel watchlist of known attacker IPs and compare with server logs
B.Enable Sysmon on the server and use its Event ID 3 (network connection) to find the IP
C.Ingest Windows Security Event logs (Event ID 4624) from the server into a Log Analytics workspace, and join with SigninLogs on account name and timestamp
D.Use the DeviceLogonEvents table in Microsoft Defender XDR advanced hunting
AnswerC

Ingesting Windows Security Event ID 4624 into a Log Analytics workspace lets the hunter join those sign-in events with SigninLogs on account name and timestamp, correlating the on-premises server compromise with the Microsoft 365 sign-in from the new IP.

Why this answer

To correlate on-premises Windows logons with Microsoft 365 sign-ins, the hunter must ingest Windows Security Event ID 4624 (successful logon) from the server into a Log Analytics workspace, then join with the SigninLogs table on account name and timestamp. This is the standard Sentinel correlation pattern for cross-domain attacks. Event ID 4624 captures the account and logon type, enabling linkage to cloud sign-ins.

Exam trap

SC-200 often tests whether candidates know which table holds which data — the trap is choosing DeviceLogonEvents (Defender XDR) when the requirement is on-premises Windows Event Logs joined with SigninLogs in Sentinel.

How to eliminate wrong answers

Option A is wrong because a watchlist of attacker IPs does not correlate server logs with sign-in logs — it only enriches, and it assumes the IP is already known. Option B is wrong because Sysmon Event ID 3 records network connections, not logon events, and does not provide the account-to-signin correlation needed. Option D is wrong because DeviceLogonEvents in Defender XDR covers device logons from Defender for Endpoint, not on-premises Windows Security Event logs, and does not directly join with Microsoft 365 SigninLogs.

52
MCQhard

You are a threat hunter at Fabrikam. You suspect that an attacker is using the Win32_Process class to create a process on a remote workstation via WMI. You need to write an advanced hunting query in Microsoft Defender XDR to detect this activity. Which table should you query to find WMI process creation events?

A.DeviceProcessEvents
B.DeviceEvents
C.DeviceNetworkEvents
D.DeviceRegistryEvents
AnswerB

DeviceEvents includes various event types, such as WmiProcessCreate, which specifically logs process creation via WMI. This table captures the WMI provider host process, the command line, and the remote caller, allowing you to detect remote WMI process creation. Querying DeviceEvents for ActionType == 'WmiProcessCreate' is the correct approach for this scenario.

Why this answer

To detect WMI process creation, you need to query a table that specifically logs WMI activity. In Microsoft Defender XDR advanced hunting, the DeviceEvents table includes an ActionType called WmiProcessCreate that captures process creation via WMI, including the remote caller and command line. Filtering DeviceEvents for this ActionType will surface the relevant events.

Exam trap

The trap here is assuming that all process creation events are in DeviceProcessEvents, but WMI-specific process creation is logged in DeviceEvents with a distinct ActionType.

53
MCQhard

Refer to the exhibit. You are reviewing a custom hunting query in Microsoft Defender XDR. The query aims to identify devices with more than 100 outbound connections in the last 30 days to IPs that appear in active threat intelligence indicators. However, the query returns no results. What is the most likely cause?

A.The RemoteIPType filter for 'Public' excludes all internal IPs, but devices connect to internal IPs mostly.
B.The join on RemoteIP and NetworkIP is mismatched because one is IPv4 and the other IPv6.
C.The ThreatIntelligenceIndicator table does not contain any indicators with an Active status that match the remote IPs.
D.The ConnectionCount threshold of 100 is too high; most devices do not exceed this.
AnswerC

This is the most plausible reason: in a KQL inner join, only rows with matching keys are returned. If the ThreatIntelligenceIndicator table contains no indicators with an Active status that equal any of the observed RemoteIP values, the joined result set will be empty by design. Indicators that are expired or have another status are filtered out, and the TI lookup data may simply not include the IPs the devices are connecting to. This aligns with the classic behavior where an inner join produces zero rows when the right side lacks matches.

Why this answer

The most likely cause is that the ThreatIntelligenceIndicator table does not contain any active indicators that match the remote IPs from the DeviceNetworkEvents. The query uses an inner join between DeviceNetworkEvents and ThreatIntelligenceIndicator on RemoteIP and NetworkIP. If there are no matching indicators, the join produces zero results.

Option A is incorrect because filtering for public IPs is correct for outbound connections to the internet. Option B is incorrect because IP version mismatch would cause a join failure, but the query would still return results if the version matched. Option D is incorrect because the threshold of 100 connections may be high, but if there were matching indicators, some devices would return results.

54
MCQeasy

You are using Microsoft Sentinel UEBA to hunt for insider threats. Which entity type would you investigate to detect unusual access to sensitive data?

A.IP
B.Application
C.Device
D.User
AnswerD

The user entity is the core anchor for UEBA in Microsoft Sentinel, enabling the engine to build a behavioral baseline and detect anomalies like unusual logon times, failed logins, or peers' rare access to sensitive resources. Insider threat hunting depends on correlating identity, access, and action attributes around a unique user, which is why user entity analysis correctly identifies abnormal access patterns. Without user-level behavioral analytics, insider threats that leverage legitimate credentials would remain undetected.

Why this answer

Microsoft Sentinel UEBA builds behavior profiles around entity types including User, Host, IP, and Application. To detect insider threats involving unusual access to sensitive data, the User entity is the right focus because UEBA tracks each user's normal data access patterns, peer group comparisons, and anomalies like accessing files or sites they normally do not. Investigating the User entity surfaces deviations such as mass downloads, access outside normal hours, or access to sensitive SharePoint sites.

Exam trap

SC-200 often tests entity-type selection by presenting IP, Device, and Application as plausible alternatives — candidates must recognize that insider data-access anomalies are modeled on the User entity, not infrastructure entities.

How to eliminate wrong answers

Option A is wrong because the IP entity is useful for detecting anomalous network origins or impossible travel, but it does not directly model a user's data access behavior or peer group. Option B is wrong because the Application entity focuses on application usage anomalies (e.g., unusual app access), not the user's access to sensitive data. Option C is wrong because the Device entity tracks device behavior and anomalies (e.g., unusual processes), but insider data access is best modeled at the user level where peer group and access patterns are analyzed.

55
MCQmedium

As a threat hunter, you want to proactively search for signs of privilege escalation using the 'AzureHound' tool within your Microsoft Sentinel environment. Which data source is most relevant to ingest to detect AzureHound usage?

A.Azure VM Insights logs
B.Azure Active Directory Audit Logs (now Microsoft Entra ID Audit Logs)
C.Azure Storage analytics logs
D.Azure Network Watcher logs
AnswerB

AzureHound enumerates Microsoft Entra ID objects, users, groups and role assignments via the Graph API, so Microsoft Entra ID Audit Logs capture the directory read and consent activity that reveals enumeration. These logs expose the reconnaissance patterns AzureHound generates.

Why this answer

AzureHound queries the Microsoft Graph API to gather Azure AD data, and those API calls are logged in the Azure Active Directory Audit Logs (Microsoft Entra ID Audit Logs). Option A is incorrect because AzureHound does not run on VMs; it is a standalone tool that uses Graph API. Option C is incorrect because AzureHound does not interact with Azure Storage.

Option D is incorrect because Azure Network Watcher logs do not capture Azure AD API activity.

56
MCQhard

You are a security analyst at a company that uses Microsoft Sentinel and Microsoft Defender for Identity (now part of Microsoft Defender XDR). During a threat hunt, you need to identify potential golden ticket attacks. You have Windows Security Events (Event ID 4672: Special Logon) and Kerberos service ticket events (Event ID 4769) ingested. A golden ticket attack often involves service ticket requests with unusual encryption types or ticket options. You want to find service ticket requests (4769) that have TicketOptions containing '0x40810000' (forwardable, renewable, canonicalize) and TicketEncryptionType == '0x17' (RC4), which are common in attacks. You need to write a KQL query that returns the top 10 accounts requesting such tickets in the last 7 days. Which query should you use?

A.SecurityEvent | where EventID == 4769 | where TicketOptions == "0x40810000" | summarize count() by AccountName | top 10 by count_
B.SecurityEvent | where EventID == 4769 | where TicketOptions == "0x40810000" and TicketEncryptionType == "0x17" | summarize count() by AccountName | top 10 by count_
C.SecurityEvent | where EventID == 4672 | where TicketOptions == "0x40810000" and TicketEncryptionType == "0x17" | summarize count() by AccountName | top 10 by count_
D.SecurityEvent | where EventID == 4769 | where TicketOptions contains "0x40810000" and TicketEncryptionType contains "0x17" | summarize count() by AccountName | top 10 by count_
AnswerB

Matching EventID 4769 with TicketOptions "0x40810000" and TicketEncryptionType "0x17" isolates RC4-encrypted, forwardable, renewable service ticket requests typical of golden ticket activity, then summarising count() by AccountName and taking the top 10 surfaces the most prolific requesters.

Why this answer

The correct query filters SecurityEvent for EventID 4769 (Kerberos service ticket request), then applies exact-match conditions on TicketOptions == "0x40810000" and TicketEncryptionType == "0x17" to identify RC4-encrypted, forwardable/renewable/canonicalize tickets typical of golden ticket attacks. It then summarizes counts by AccountName and returns the top 10, matching the requirement precisely.

Exam trap

SC-200 often tests event ID confusion — candidates must remember 4769 is for service ticket requests, while 4672 is for special logon, and must use exact match for hex values.

How to eliminate wrong answers

Option A is wrong because it omits the TicketEncryptionType filter, so it would include legitimate AES-encrypted tickets and produce false positives. Option C is wrong because it filters on EventID 4672 (Special Logon) instead of 4769, which is the wrong event for service ticket requests. Option D is wrong because it uses the contains operator instead of ==, which could match partial strings and is less precise; exact match is required for these specific hex values.

57
MCQhard

You are reviewing a hunting query. What is the primary purpose of this query?

A.List all users with any risk level during sign-in in the last 7 days
B.Detect users who have granted admin consent to malicious OAuth apps
C.Find users with medium-risk sign-ins that share IP addresses with service principal sign-ins, indicating possible token theft or lateral movement
D.Identify service principals that have been compromised and are performing high-risk sign-ins
AnswerC

This option correctly describes the query's purpose: it starts with medium-risk user sign-ins, joins those with service principal sign-ins on the same IP address, and uses a count threshold to identify repeated correlation. Such a pattern can reveal token theft or lateral movement where an attacker uses a stolen user token from an IP also associated with a service principal. The combination of the risk level on the user sign-in and the shared IP with a service principal is the key investigative signal.

Why this answer

The query filters for users with medium risk sign-ins and joins with service principal sign-ins on IP address, then counts occurrences per user exceeding 5, indicating potential compromise involving both user and service principal activity from the same IP. Option A is wrong because it does not focus on service principal compromise alone. Option B is wrong because it does not look for admin consent grants.

Option D is wrong because it uses only medium risk, not high.

58
MCQmedium

A threat hunter is using Microsoft Defender for Endpoint advanced hunting to investigate a suspicious process that was observed launching from a temporary folder. The hunter wants to find all devices that have executed this specific process (with the same SHA256 hash) in the last 24 hours. Which table and column should be used in the query?

A.DeviceNetworkEvents table, SHA256 column
B.DeviceEvents table, SHA256 column
C.DeviceProcessEvents table, SHA256 column
D.DeviceFileEvents table, SHA256 column
AnswerC

DeviceProcessEvents records process creation events and exposes the SHA256 column, letting the hunter filter executions by the exact file hash observed. This satisfies the 24-hour scope via Timestamp filtering, returning every device that ran that specific binary regardless of filename or path.

Why this answer

DeviceProcessEvents table tracks process execution events and includes the SHA256 column for the file hash. Therefore, Option C is correct. Option A (DeviceNetworkEvents) is for network connections and does not include SHA256.

Option B (DeviceEvents) is a generic table that may not include process hash. Option D (DeviceFileEvents) is for file creation/modification, not execution.

59
Multi-Selecthard

Which THREE actions are recommended when conducting a threat hunting exercise in Microsoft Sentinel using the MITRE ATT&CK framework?

Select 3 answers
A.Focus only on techniques that have not been seen in your environment before.
B.Use the hunting queries from the Microsoft Sentinel Content hub as a starting point.
C.Rely exclusively on automated detection rules to identify threats.
D.Document your findings and update detection rules based on new patterns discovered.
E.Map your hunting hypotheses to specific MITRE ATT&CK tactics and techniques.
AnswersB, D, E

Content hub hunting queries map to MITRE ATT&CK tactics and techniques, giving you pre-built KQL aligned to the framework's structure. This satisfies the scenario's requirement to conduct hunting within ATT&CK, letting you pivot from known technique coverage rather than authoring detections from scratch.

Why this answer

Options B, D, and E are recommended actions. B: Using hunting queries from the Microsoft Sentinel Content hub provides a validated starting point. D: Documenting findings and updating detection rules helps improve future hunts.

E: Mapping hypotheses to MITRE ATT&CK tactics and techniques ensures comprehensive coverage. A is incorrect because focusing only on unseen techniques ignores known threats that may still be active. C is incorrect because relying exclusively on automated detection rules can miss advanced persistent threats that require manual hunting.

60
MCQmedium

Your team is using Microsoft 365 Defender advanced hunting to investigate a possible data exfiltration incident. The security team suspects that an internal attacker used a compromised SharePoint Online account to download sensitive files from multiple sites. You need to build a hunting query that identifies all file download activities from SharePoint Online for a specific user account over the past 7 days, and then calculates the total size of downloaded files. Which KQL query should you use?

A.CloudAppEvents | where Application == 'SharePoint Online' and ActionType == 'FileDownload' and AccountDisplayName == 'targetuser@contoso.com' and Timestamp > ago(7d) | summarize TotalSize = sum(FileSize)
B.CloudAppEvents | where Application == 'SharePoint Online' and ActionType == 'FileDownloaded' and AccountDisplayName == 'targetuser@contoso.com' and Timestamp > ago(7d) | summarize TotalSize = sum(FileSize)
C.EmailEvents | where Application == 'SharePoint Online' and ActionType == 'FileDownloaded' and AccountDisplayName == 'targetuser@contoso.com' and Timestamp > ago(7d) | summarize TotalSize = sum(FileSize)
D.FileEvents | where Application == 'SharePoint Online' and ActionType == 'FileDownloaded' and AccountDisplayName == 'targetuser@contoso.com' and Timestamp > ago(7d) | summarize TotalSize = sum(FileSize)
AnswerB

This query is correct because it uses the CloudAppEvents table, the authoritative table in Microsoft 365 Defender advanced hunting for cloud app activities, and filters on ActionType == 'FileDownloaded', which is the exact event name for file downloads in SharePoint Online. The AccountDisplayName filter isolates the target user's actions within the last 7 days, and summarize TotalSize = sum(FileSize) correctly aggregates the FileSize numeric column to yield the total bytes downloaded. It is the only option that combines the right table, accurate action type, and proper aggregation.

Why this answer

Ly filters SharePoint file download events (FileDownloaded) and sums the FileSize. Option A uses wrong action; Option C uses wrong table; Option D is for email.

61
Multi-Selectmedium

Which TWO techniques are commonly used in threat hunting with Microsoft Sentinel to identify lateral movement? (Choose two.)

Select 2 answers
A.Detecting port scanning activity from internal IPs.
B.Searching for multiple failed logon attempts from a single IP.
C.Looking for mass file deletion events on file servers.
D.Correlating service account usage with anomalous network connections.
E.Identifying remote PowerShell execution across multiple machines.
AnswersD, E

Service accounts often have elevated privileges and allow remote connections (e.g., SMB, WinRM, RDP) to multiple systems for legitimate application workloads. When an attacker compromises a service account, correlating its historical baseline with anomalous outbound network connections—such as connections to previously unseen hosts or non-standard protocols—can reveal lateral movement attempts that would otherwise blend in with normal service traffic.

Why this answer

Option D is correct because correlating service account usage with anomalous network connections surfaces lateral movement: attackers frequently reuse service accounts (often over SMB/RPC or WinRM) to pivot between hosts, and Microsoft Sentinel can join identity logs (SecurityEvent 4624 logon type 3/9, Azure AD sign-in logs) with network telemetry (Syslog, CEF, or NSG flow logs) in KQL to flag a service account authenticating to hosts it never normally touches. Option E is correct because remote PowerShell execution across multiple machines is a classic lateral movement technique; Sentinel detects it via Event ID 4104 (PowerShell script block logging), 4688 process creation showing powershell.exe with -Command/-EncodedCommand, and WinRM operational logs (e.g., Microsoft-Windows-WinRM/Operational), especially when the same account spawns sessions on many hosts in a short window. Option A is not the best fit because port scanning is typically reconnaissance or discovery activity that precedes movement rather than lateral movement itself.

Option B describes brute-force or password-spray credential access, which is an earlier attack phase, not lateral movement. Option C, mass file deletion, indicates impact or ransomware behavior rather than host-to-host pivoting.

Exam trap

SC-200 often tests whether candidates can distinguish lateral movement from adjacent phases — brute force (credential access) and mass deletion (impact) are common distractors that sound related but belong to different ATT&CK tactics.

62
MCQeasy

You are hunting for signs of ransomware in your environment using Microsoft 365 Defender. Which advanced hunting table should you primarily query to detect file encryption events?

A.DeviceNetworkEvents
B.DeviceProcessEvents
C.DeviceFileEvents
D.DeviceRegistryEvents
AnswerC

DeviceFileEvents records file creation, modification and renaming activity from Defender for Endpoint, capturing the rapid, high-volume write and rename operations ransomware performs during encryption. This directly satisfies the stem's requirement to detect file encryption events, unlike tables covering process, network or registry activity.

Why this answer

DeviceFileEvents captures file creation, modification, and deletion events, which are typical for ransomware encryption. Option A (DeviceNetworkEvents) is wrong because it captures network connections, not file events. Option B (DeviceProcessEvents) is wrong because it captures process creation and termination, not file events.

Option D (DeviceRegistryEvents) is wrong because it captures registry modifications, not file events.

63
MCQmedium

You are a threat hunter using PowerShell on a Windows 10 device. The command returns no output for a known threat ID. What is the most likely reason?

A.The Get-MpThreat cmdlet is deprecated.
B.The threat ID format is incorrect.
C.The threat has already been remediated and is no longer in the active threats list.
D.PowerShell must be run as administrator.
AnswerC

The query targets the active threats collection, which only holds unresolved detections. Once remediation completes, the threat moves out of that list, so querying by that ID returns nothing even though the historical record may still exist elsewhere.

Why this answer

Get-MpThreat returns only currently active (unremediated) threats detected by Microsoft Defender Antivirus. If a known threat ID returns no output, the most likely explanation is that the threat was already remediated and removed from the active threats list, so the cmdlet has nothing to return.

Exam trap

SC-200 often tests that Get-MpThreat only shows active threats — candidates assume empty output means the cmdlet failed or the ID was wrong, rather than the threat being remediated.

How to eliminate wrong answers

Option A is wrong because Get-MpThreat is a current, supported Defender PowerShell cmdlet and is not deprecated. Option B is wrong because an incorrect threat ID format would typically produce a parameter/format error rather than silent empty output, and the question states the ID is 'known.' Option D is wrong because Get-MpThreat can be run without elevation for read operations; lack of admin rights would produce an access-denied error, not empty output.

64
MCQmedium

During a threat hunt in Microsoft Sentinel, you find a query that returns a high number of false positives. Which action should you take to refine the hunt?

A.Increase the query time range to gather more data
B.Create a scheduled alert rule based on the query
C.Remove columns from the result set to simplify analysis
D.Add additional filters to the query to exclude known benign activity
AnswerD

Adding filters that exclude known benign activity narrows the result set, directly reducing the false positives the hunt query returns. This refines the analytic without disabling it, satisfying the requirement to tune detection logic so genuine threats remain visible while routine noise is suppressed.

Why this answer

Adding filters to exclude known benign activity directly reduces false positives by narrowing the result set to only suspicious events. In Microsoft Sentinel, KQL queries are refined iteratively during threat hunts, and excluding known-good indicators (e.g., service accounts, approved IP ranges, signed binaries) is the standard tuning technique. This preserves the hunt's detection intent while improving signal-to-noise ratio.

Exam trap

SC-200 often tests the misconception that more data or more alerting equals better hunting — candidates pick 'increase time range' or 'create an alert rule' when the real fix is query-level tuning to suppress benign activity.

How to eliminate wrong answers

Option A is wrong because increasing the query time range returns even more data and typically amplifies false positives rather than reducing them. Option B is wrong because creating a scheduled alert rule from a noisy query would generate alert fatigue and is premature before tuning — analytics rules should be built only after the query is validated. Option C is wrong because removing columns only changes the display of results; it does not affect which rows match, so false positives remain in the result set.

65
Multi-Selectmedium

Which TWO data sources are essential for threat hunting in Microsoft Sentinel to detect lateral movement?

Select 2 answers
A.Microsoft Entra ID sign-in logs
B.DeviceNetworkEvents (Microsoft Defender for Endpoint)
C.SecurityEvent (Windows Event Logs)
D.CommonSecurityLog (Syslog)
E.DnsEvents
AnswersB, C

DeviceNetworkEvents is the workflow's core because it reveals each process's outbound and inbound network connections, including remote IP, remote port, protocol, and the initiating process image. Lateral movement requires a connection to another host via protocols like SMB (445), RDP (3389), or WinRM (5985), so hunting can simply look for unusual or repetitive connection patterns from a compromised host to internal addresses. This table also lets you join to process creation events, making it indispensable for reconstructing the full attack chain between systems.

Why this answer

DeviceNetworkEvents (Microsoft Defender for Endpoint) provides network connections between devices, which can reveal lateral movement attempts. SecurityEvent (Windows Event Logs) provides security-related events such as remote logons (Event ID 4624) and service creation (Event ID 7045), which are key indicators of lateral movement. Option A (Microsoft Entra ID sign-in logs) focuses on cloud identity and is not directly relevant for on-premises lateral movement.

Option D (CommonSecurityLog) typically comes from network perimeter devices and is not essential for internal lateral movement. Option E (DnsEvents) can provide insight into DNS queries but is less essential than the other two data sources for detecting lateral movement.

66
MCQhard

Refer to the exhibit. A custom detection rule in Microsoft Sentinel uses this JSON definition. An analyst notices that the rule is generating alerts for legitimate administrative scripts launched from File Explorer. What is the best way to reduce false positives while retaining detection of malicious Office-based PowerShell launches?

A.Add an additional filter to exclude PowerShell executions from specific administrative user accounts
B.Increase the query time range to 30 days
C.Change the severity to Informational to suppress alerts
D.Remove the parent process filter and rely only on FileName == 'powershell.exe'
AnswerA

Excluding known admin accounts helps reduce noise while keeping detection for other users.

Why this answer

Adding conditions to exclude known administrative scenarios (e.g., specific user accounts) reduces false positives without removing the parent process filter entirely. Option B is wrong because removing the parent process filter would broaden detection, likely increasing false positives. Option C is wrong because lowering severity does not reduce false positives.

Option D is wrong because increasing time range does not help.

67
MCQeasy

You are hunting for suspicious scheduled tasks that could be used for persistence. Which Microsoft 365 Defender advanced hunting table contains information about scheduled tasks?

A.IdentityLogonEvents
B.DeviceEvents
C.DeviceNetworkEvents
D.DeviceProcessEvents
AnswerB

DeviceEvents is the correct table because it contains a wide range of Windows security events, including Event ID 4698 which is specifically the creation of a scheduled task. This table ingests events from the Windows Event Log and is the primary place to hunt for persistence mechanisms like new scheduled tasks. You can also find related events like task updates (4702) and deletions (4699) here. So for identifying suspicious scheduled task creation, DeviceEvents is the authoritative source.

Why this answer

DeviceEvents in Microsoft 365 Defender advanced hunting is the correct table because it captures a wide range of system and security events, including scheduled task creation, modification, and deletion. Specifically, it logs events like 'ScheduledTaskCreated' and 'ScheduledTaskModified' under the ActionType column, which are essential for detecting persistence mechanisms. Other tables focus on different telemetry: IdentityLogonEvents for authentication, DeviceNetworkEvents for network connections, and DeviceProcessEvents for process creation.

Thus, DeviceEvents is the only table that directly contains scheduled task information.

Exam trap

SC-200 often tests the distinction between process execution and system event logging, causing candidates to mistakenly choose DeviceProcessEvents when asked about scheduled task creation, even though the actual task registration is recorded in DeviceEvents.

How to eliminate wrong answers

Option A is wrong because IdentityLogonEvents records logon and authentication events (e.g., interactive, network, and remote interactive logons) in Azure AD and on-premises systems, not scheduled task activities. Option C is wrong because DeviceNetworkEvents captures network connection events such as TCP/UDP traffic, DNS queries, and HTTP requests, not file system or task scheduler changes. Option D is wrong because DeviceProcessEvents logs process creation and termination events (e.g., ProcessCreate, ProcessTerminate), which may include the execution of schtasks.exe but does not contain the actual scheduled task creation or modification events themselves.

68
MCQeasy

You are hunting for possible data exfiltration via email in Microsoft 365. Which data source in Microsoft Sentinel provides the most relevant telemetry for email forwarding rules?

A.Microsoft Defender for Cloud Apps logs
B.Windows Security Events
C.Azure AD sign-in logs
D.Office 365 audit logs (Exchange)
AnswerD

Office 365 audit logs, specifically the Exchange workload, are the authoritative source because they capture changes to mailbox forwarding and inbox rules. Operations like Set-Mailbox, which includes modifications to ForwardingSmtpAddress, and New-InboxRule or Set-InboxRule with RedirectTo are logged with the actor's UPN, the exact timestamp, and the target mailbox. These events are accessible via the Microsoft Purview compliance portal or the Search-UnifiedAuditLog cmdlet, making them the definitive evidence for a data exfiltration via email investigation.

Why this answer

Office 365 audit logs (Exchange) capture mailbox-level activity including the New-InboxRule, Set-InboxRule, and Set-Mailbox operations that create or modify forwarding rules (ForwardTo, RedirectTo, ForwardAsAttachmentTo). This is the authoritative telemetry source for detecting email-based exfiltration via auto-forwarding in Microsoft 365. Defender for Cloud Apps can surface anomalies but relies on the same underlying audit stream, making the native Office 365 audit log the most direct and complete source.

Exam trap

SC-200 often tests whether candidates confuse CASB-level anomaly detection (Defender for Cloud Apps) with the raw audit telemetry that actually records the malicious configuration change — the audit log is the source of truth, not the analytics layer.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender for Cloud Apps provides CASB-style anomaly detection and app governance signals but does not itself contain the raw Exchange mailbox rule creation events — it consumes them from the Office 365 audit pipeline. Option B is wrong because Windows Security Events cover on-premises host authentication, process, and object access activity (4624, 4688, 4663) and have no visibility into Exchange Online mailbox rules. Option C is wrong because Azure AD sign-in logs record authentication events (interactive and non-interactive sign-ins, conditional access results) and do not capture mailbox configuration changes such as forwarding rules.

69
MCQeasy

A threat hunter in Microsoft Sentinel wants to detect attempts to disable security logging on Windows servers using a KQL query. Which Windows Event ID should the query filter on to capture security log clearing events?

A.4688
B.4624
C.5145
D.1102
AnswerD

Event ID 1102 records the Windows security audit log being cleared, written to the Security log whenever someone runs wevtutil or clears it via Event Viewer. Filtering on 1102 in the KQL query therefore surfaces exactly the anti-forensic behaviour the hunter targets, satisfying the requirement to detect security logging being disabled on those servers.

Why this answer

Event ID 1102 in the Windows Security log indicates the security log was cleared, which is a common technique used by attackers to cover their tracks. Option A (4688) is for process creation. Option B (4624) is for successful logon.

Option C (5145) is for network share access. Therefore, only Option D (1102) correctly captures security log clearing events.

70
Multi-Selecthard

Which THREE techniques are effective for hunting for living-off-the-land (LotL) attacks using Microsoft Sentinel?

Select 3 answers
A.Monitoring for installation of third-party software on endpoints.
B.Hunting for WMI activity using Event ID 5861 and correlating with process creation events.
C.Tracking non-interactive logon sessions (Logon Type 5).
D.Analyzing PowerShell script block logs (Event ID 4104) for encoded commands or unusual parameters.
E.Correlating remote service creation events (Event ID 7045) with network connections from administrative tools.
AnswersB, D, E

Event ID 5861 in the Microsoft-Windows-WMI-Activity/Operational log records the registration or modification of a permanent WMI event subscription, including the originating ProcessID and the consumer/filter details. Attackers commonly use WMI as a LotL lateral movement technique, so correlating this event with Windows process creation (Event ID 4688) reveals the exact command line, such as wmic.exe or PowerShell, that created the subscription. Without that correlation, 5861 can be mistaken for legitimate administrative tooling.

Why this answer

Option B is correct because WMI is a native Windows administration mechanism frequently abused for LotL execution and persistence, and Event ID 5861 (WMI permanent event subscription creation in the WMI-Activity operational log) combined with process creation telemetry (e.g., Event ID 4688/Sysmon Event ID 1) exposes malicious subscription-based persistence and spawned processes. Option D is correct because PowerShell script block logging (Event ID 4104) captures de-obfuscated script content, making it effective for detecting encoded commands (-EncodedCommand), download cradles, and unusual parameters typical of LotL tradecraft. Option E is correct because correlating service installation (System log Event ID 7045) with subsequent network connections from administrative tools such as PsExec, sc.exe, or SMB/RPC traffic reveals lateral movement and remote execution that rely on built-in utilities.

Option A does not belong because installing third-party software is not living-off-the-land activity, which by definition uses pre-installed, signed system binaries. Option C does not belong because Logon Type 5 is a service logon, and while service accounts can be abused, tracking non-interactive service logons alone is not a specific or effective LotL hunting technique compared with the correlated event-based methods above.

Exam trap

SC-200 often tests the confusion between general security monitoring and specific LotL hunting techniques, leading candidates to select generic activities like software installation or logon type tracking.

71
MCQeasy

As part of a threat hunt, you want to find instances where a user successfully authenticated to multiple applications within a short time using different IP addresses. Which Microsoft 365 Defender data source would be most appropriate?

A.CloudAppEvents
B.DeviceLogonEvents
C.IdentityLogonEvents
D.AlertInfo
AnswerC

IdentityLogonEvents is the correct table because it is specifically designed to capture authentication events to applications using Microsoft Entra ID (Azure AD). Each row represents a user authentication attempt to a cloud app, with details such as the target application, logon type, protocol, and whether the attempt succeeded or failed. This directly matches the requirement to find instances of authentication to a cloud application, making it the authoritative source for this hunt.

Why this answer

IdentityLogonEvents contains authentication events for cloud apps, with columns like Application, IP address, and Timestamp.

72
MCQeasy

You are threat hunting for signs of credential dumping via LSASS access. Which Advanced Hunting schema table in Microsoft Defender XDR should you primarily query to find processes that opened a handle to LSASS?

A.DeviceProcessEvents
B.DeviceEvents
C.DeviceNetworkEvents
D.DeviceRegistryEvents
AnswerB

DeviceEvents is the correct table because it stores security-sensitive behavioral events, and specifically the ActionType 'LsassAccessedByProcess' is emitted when a process attempts to open the LSASS process handle with credential-theft access rights such as PROCESS_VM_READ or PROCESS_ALL_ACCESS. This event directly indicates a potential credential-dumping attempt, making it the definitive data source for this hunt. Other tables may show supporting artifacts, but only DeviceEvents captures the actual LSASS access.

Why this answer

DeviceEvents is the correct table because it captures a broad set of endpoint telemetry including process access events, which is where LSASS handle-opening activity is recorded. When a tool like Mimikatz or a credential-dumping utility opens a handle to lsass.exe with read access, that action surfaces in DeviceEvents with ActionType values such as 'ProcessAccess' and fields identifying the source and target processes. DeviceProcessEvents only records process creation, so it would not show the handle open itself.

Exam trap

SC-200 often tests the distinction between DeviceProcessEvents (process creation) and DeviceEvents (broader telemetry including ProcessAccess) — candidates who assume 'process' events cover LSASS access pick the wrong table.

How to eliminate wrong answers

Option A is wrong because DeviceProcessEvents records process creation and termination events (e.g., a new process starting), not the act of one process opening a handle to another — so it would miss the LSASS access itself. Option C is wrong because DeviceNetworkEvents captures network connections and DNS activity, which is unrelated to local handle operations on LSASS. Option D is wrong because DeviceRegistryEvents records registry key and value modifications, not process memory access or handle operations.

73
Multi-Selectmedium

Which THREE data sources in Microsoft Sentinel are most useful for threat hunting activities related to identity compromise?

Select 3 answers
A.SecurityEvent
B.SigninLogs
C.CommonSecurityLog
D.AuditLogs
E.OfficeActivity
AnswersA, B, D

SecurityEvent is a core Windows event log source in Sentinel, capturing event IDs such as 4624 (successful logon), 4625 (failed logon), 4672 (special privileges), and 4720 (user account created). Because it includes logon types and account logon details, it directly supports detection of brute-force attacks, pass-the-hash, and lateral movement across managed endpoints. Without this table, identity-focused hunts would lack the fine-grained audit trails of OS-level authentication and authorization.

Why this answer

SecurityEvent (A) is correct because it captures Windows Security event log data such as 4624/4625 logons, 4672 special privileges, and 4720/4728 account and group changes, which are essential for detecting credential theft, lateral movement, and privilege escalation tied to identity compromise. SigninLogs (B) is correct because it holds Microsoft Entra ID sign-in telemetry including result type, conditional access status, risk detections, IP/location, and MFA details, directly exposing brute-force, password spray, impossible travel, and token replay activity. AuditLogs (D) is correct because it records Entra ID directory changes such as role assignments, consent grants, credential additions, and user/group modifications that attackers use to persist or escalate after compromising an identity.

CommonSecurityLog (C) is not among the correct answers because it carries third-party CEF/Syslog data (firewalls, proxies, IDS) rather than native identity authentication events. OfficeActivity (E) is not among the correct answers because it reflects Microsoft 365 workload operations (SharePoint, Exchange, Teams) and, while useful for post-compromise activity, is less directly focused on identity compromise than the authentication and directory sources.

Exam trap

SC-200 often tests the distinction between identity-focused logs (SigninLogs, AuditLogs) and network/device logs (CommonSecurityLog), causing candidates to overlook AuditLogs for identity compromise.

74
MCQeasy

A security analyst is hunting for signs of credential dumping using Microsoft Defender for Endpoint. Which advanced hunting query should the analyst use to detect the use of Mimikatz?

A.DeviceRegistryEvents where RegistryKey contains 'mimikatz'
B.DeviceProcessEvents where ProcessCommandLine contains 'mimikatz'
C.DeviceFileEvents where FileName contains 'mimikatz'
D.DeviceNetworkEvents where RemoteIP contains 'mimikatz'
AnswerB

DeviceProcessEvents capture process creation events, including the full command line, which is exactly where Mimikatz's execution appears—for example, 'mimikatz.exe privilege::debug sekurlsa::logonpasswords'. Searching ProcessCommandLine for 'mimikatz' directly detects the tool being run, even if the executable is renamed, as long as the command line includes the name. This is the most dependable hunting query because credential dumping requires process execution, and process creation logs are the primary telemetry for that activity.

Why this answer

Mimikatz is executed as a process, and its invocation (e.g., 'mimikatz.exe', 'Invoke-Mimikatz', or sekurlsa::logonpasswords) appears in the process command line. Microsoft Defender for Endpoint's DeviceProcessEvents table captures ProcessCommandLine, making it the correct table for detecting execution-based credential dumping. This is the standard hunting pattern for tool-name or command-line-based detection.

Exam trap

The trap is that candidates pick the table that sounds most 'security-related' (registry or network) instead of recognizing that tool execution and command-line arguments are always captured in DeviceProcessEvents — the exam tests whether you know which MDE table holds which telemetry type.

How to eliminate wrong answers

Option A is wrong because DeviceRegistryEvents captures registry key modifications, and while Mimikatz can touch registry keys (e.g., WDigest), the tool name itself is not a registry key — this query would return nothing useful. Option C is wrong because DeviceFileEvents tracks file creation/modification, and while mimikatz.exe may exist as a file, hunting by filename alone misses renamed binaries and does not capture the credential-dumping behavior. Option D is wrong because DeviceNetworkEvents records network connections with IP addresses and ports; 'mimikatz' is not an IP address, so this query is syntactically and semantically invalid for the hunt.

75
MCQhard

A threat hunter wants to proactively identify devices that may have been compromised by a known adversary using DLL side-loading techniques. Which Microsoft Sentinel solution or feature should the hunter leverage to create custom detection rules based on the latest threat intelligence?

A.User and Entity Behavior Analytics (UEBA)
B.Automation rules with playbooks
C.Custom workbooks
D.Threat Intelligence integration with analytics rules
AnswerD

Ingesting threat intelligence indicators into Microsoft Sentinel and mapping them to analytics rules lets hunters build custom detections for DLL side-loading observables, such as malicious file hashes or loaded modules, matching the requirement to use the latest threat intelligence proactively.

Why this answer

Microsoft Sentinel's Threat Intelligence integration allows you to import threat indicators (IOCs) from various sources and use them in analytics rules to detect known adversary techniques like DLL side-loading. By creating custom analytics rules that reference threat intelligence data, the hunter can proactively identify compromised devices based on the latest intel. This directly addresses the requirement to leverage threat intelligence for custom detection.

Exam trap

The trap is assuming that UEBA or automation rules provide threat intelligence-based detection, but only the Threat Intelligence integration with analytics rules enables custom detection using external IOCs.

How to eliminate wrong answers

Option A is wrong because UEBA focuses on behavioral anomalies and does not directly incorporate external threat intelligence feeds for custom detection rules. Option B is wrong because automation rules with playbooks are for orchestrating responses, not for creating detection logic based on threat intelligence. Option C is wrong because custom workbooks are for visualization and reporting, not for generating detection rules.

Page 1 of 3 · 178 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Perform threat hunting questions.