Courseiva

CCNA Perform threat hunting Questions

75 of 178 questions · Page 2/3 · Perform threat hunting · Answers revealed

76
MCQmedium

You are a security analyst at Fabrikam. The company uses Microsoft Defender for Cloud Apps and Microsoft Sentinel. During a threat hunt, you need to identify users who are accessing cloud applications from multiple geographic locations in a short time, which could indicate credential theft or token replay. You want to create a hunting query in Microsoft Sentinel using the CloudAppEvents table. Which approach should you take?

A.Query CommonSecurityLog for VPN connections
B.Query OfficeActivity for sign-in logs
C.Query SecurityAlert for location-related alerts
D.Query CloudAppEvents, summarize by AccountDisplayName and bin(TimeGenerated, 1h), then use dcount(CountryCode) > 1
AnswerD

Summarising CloudAppEvents by AccountDisplayName within one-hour bins and filtering where dcount(CountryCode) exceeds one directly surfaces impossible-travel patterns, satisfying the requirement to detect users accessing cloud apps from multiple geographies in a short window. The CloudAppEvents table supplies the CountryCode and TimeGenerated fields this aggregation depends on.

Why this answer

The CloudAppEvents table in Microsoft Sentinel contains Microsoft Defender for Cloud Apps activity logs, including user sign-ins and access to cloud applications with geographic metadata such as CountryCode. Summarizing by AccountDisplayName and binning TimeGenerated into 1-hour windows, then filtering where dcount(CountryCode) > 1, directly detects the impossible-travel pattern described. This is the canonical KQL approach for multi-geo access hunting in Sentinel.

Exam trap

The trap is that candidates pick OfficeActivity or SecurityAlert because they sound like they contain sign-in or location data, but only CloudAppEvents provides the enriched cloud app access telemetry with CountryCode needed for the multi-geo dcount pattern.

How to eliminate wrong answers

Option A is wrong because CommonSecurityLog contains network security appliance logs (e.g., firewalls, proxies) and does not include cloud app user access events with CountryCode — it would not surface the credential-theft pattern. Option B is wrong because OfficeActivity covers Microsoft 365 audit events but does not include the broader cloud app access telemetry (including non-Microsoft SaaS) that CloudAppEvents provides, and it lacks the same CountryCode enrichment. Option C is wrong because SecurityAlert contains generated alerts, not raw access events, so you cannot reliably hunt for the multi-geo pattern from alerts alone.

77
MCQmedium

Your organization uses Microsoft Defender for Cloud Apps and Microsoft Sentinel. During a threat hunt, you find that a user accessed a sensitive SharePoint site from an anonymous IP address. Which hunting method would best identify all users who accessed the same site from similar anonymous IPs?

A.Query CloudAppEvents in Advanced hunting for the SharePoint site URL and filter by IP category 'AnonymousProxy'
B.Query DeviceEvents for network connections from the anonymous IP
C.Use Microsoft Purview to scan for sensitive data accessed from anonymous IPs
D.Search Azure AD sign-in logs for the same IP
AnswerA

CloudAppEvents holds Microsoft Defender for Cloud Apps activity records, including SharePoint access and the IP category field. Filtering on the site URL and AnonymousProxy identifies every user who reached that site from anonymous IPs, which Sentinel's sign-in tables cannot surface.

Why this answer

Using KQL to query CloudAppEvents for the specific SharePoint site and filtering by IP address categories (e.g., AnonymousProxy) is the most direct method. Option D (Azure AD sign-in logs) may not include SharePoint site-level access. Option B (Microsoft Defender for Endpoint) is for endpoint activities.

Option C (Microsoft Purview) focuses on data classification and governance.

78
MCQmedium

During a threat hunt, a security analyst uses Microsoft Sentinel and identifies a series of failed logon attempts from a single IP address targeting multiple user accounts. The analyst wants to create a scheduled analytics rule that generates an alert when the same IP address fails to logon to more than 10 different accounts within 5 minutes. Which KQL operator should be used to count distinct accounts per IP?

A.count()
B.summarize count() by Account
C.distinct Account
D.dcount(Account)
AnswerD

dcount(Account) counts distinct account values per grouping, so summarising by IP with a threshold above 10 flags the same source failing against many accounts within the five-minute window. It satisfies the distinct-account counting requirement precisely.

Why this answer

The dcount(Account) operator is correct because it counts the number of distinct values in the Account column, which is exactly what the analyst needs: the number of unique accounts targeted by failed logons from a single IP. The full query would use summarize dcount(Account) by IPAddress and then filter for counts greater than 10 within a 5-minute window. This directly addresses the requirement to count distinct accounts per IP.

Exam trap

SC-200 often tests the difference between count() and dcount() in KQL — candidates confuse counting all rows with counting distinct values, leading to incorrect detection logic.

How to eliminate wrong answers

Option A is wrong because count() counts all rows, not distinct accounts — it would count every failed logon event, including multiple attempts against the same account. Option B is wrong because summarize count() by Account groups by Account and counts events per account, which does not give the number of distinct accounts per IP. Option C is wrong because distinct Account is not a valid KQL operator for aggregation — distinct is used as a tabular operator to return unique rows, not as an aggregation function within summarize.

79
MCQeasy

You are threat hunting for indicators of compromise related to a known malware family. Which data source in Microsoft Defender XDR would provide the most direct evidence of malware execution on endpoints?

A.EmailEvents
B.DeviceProcessEvents
C.IdentityLogonEvents
D.DeviceNetworkEvents
AnswerB

DeviceProcessEvents captures process creation events, which directly indicate malware execution.

Why this answer

DeviceProcessEvents captures process creation events, which directly indicate malware execution. Option A is incorrect because EmailEvents only covers email data, not execution events. Option C (IdentityLogonEvents) focuses on authentication events, not process execution.

Option D (DeviceNetworkEvents) shows network connections that may occur after execution, but does not directly show execution itself.

80
MCQmedium

A threat hunter is investigating a potential malware outbreak in Microsoft Defender for Cloud Apps. The hunter notices that multiple users have installed a new app with high permissions that accesses their email. The app was not requested by IT. What is the most effective way to hunt for all instances of this app across the organization?

A.Review Conditional Access app control policies for any block rules
B.Check Microsoft 365 Defender alerts for malicious OAuth apps
C.Query the Microsoft 365 Defender advanced hunting table 'CloudAppEvents' for app installation events and then use 'AppGovernance' to list all apps
D.Use the Cloud App Security activity log to search for 'Install app' events and then review the 'App governance' dashboard for all instances
AnswerD

In Microsoft Defender for Cloud Apps, the activity log is the authoritative source for operational events, and filtering for the activity type 'Install app' directly surfaces when an OAuth app was introduced to the tenant. After identifying these installation events, the App governance dashboard provides a unified inventory of all app instances, including permissions, publisher, and usage, enabling the hunter to scope the outbreak. This sequence—find the installation event, then pivot to the governance inventory—matches the intended workflow for OAuth app threat hunting.

Why this answer

The activity log in Cloud App Security provides a comprehensive record of app installation events, and the App Governance dashboard aggregates all instances for review, making it the most effective hunting approach. Option A (conditional access policies) is reactive and not suitable for proactive hunting. Option B (Microsoft 365 Defender alerts) only surfaces known malicious apps, not all instances.

Option C (CloudAppEvents table and AppGovernance) can be used, but the activity log is more direct and complete for hunting all installations, as CloudAppEvents may not capture every installation event or may require complex queries.

81
MCQeasy

During a threat hunt, you identify a suspicious process that spawned from Microsoft Word with a command-line argument containing ' -enc '. Which hunting technique is most appropriate to investigate this further?

A.Review the PowerShell script block logging
B.Initiate network traffic analysis for the host
C.Check the file hash against threat intelligence feeds
D.Decode the base64-encoded command-line argument
AnswerA

Reviewing PowerShell script block logging could provide additional context, but it is not the most direct way to investigate an encoded command. Decoding the '-enc' argument first yields the actual command.

Why this answer

The '-enc' argument is a well-known PowerShell parameter indicating a Base64-encoded command, often used by attackers to obfuscate malicious scripts. In Microsoft Defender for Endpoint and SC-200 hunting scenarios, the most appropriate technique is to review PowerShell script block logging (Event ID 4104), which records the decoded script block content and provides the actual PowerShell code executed. This allows the analyst to understand the intent and actions of the suspicious process without manually decoding the argument.

While manual decoding can be useful, script block logging is the standard hunting technique that surfaces the decoded command directly in the telemetry.

Exam trap

SC-200 often tests the misconception that the '-enc' argument itself must be manually decoded to investigate. In reality, PowerShell script block logging (Event ID 4104) captures the decoded script block content, making it the most appropriate hunting technique. Manual decoding is a fallback when logging is not configured or the event is missing.

How to eliminate wrong answers

Option A is wrong because while PowerShell script block logging would capture the decoded script if enabled, it may not be available or may not have logged the event, and the question asks for the most appropriate technique based on the given command line. Option B is wrong because network traffic analysis, though useful, does not directly address the encoded command line and would be a subsequent step after understanding the script's behavior. Option C is wrong because checking the file hash against threat intelligence is irrelevant here; the suspicious element is the command-line argument, not a file, and the hash of Word or PowerShell would not provide insight into the encoded command.

82
MCQmedium

Refer to the exhibit. The KQL query is used for threat hunting. What is the primary purpose of this query?

A.Identify devices where cmd.exe launched PowerShell and made outbound HTTPS connections.
B.Find devices where PowerShell was used to download files.
C.Detect lateral movement using remote services.
D.Identify cmd.exe running with high integrity.
AnswerA

The query correlates DeviceProcessEvents with DeviceNetworkEvents, joining on DeviceId and a time window to link cmd.exe spawning PowerShell with subsequent outbound HTTPS traffic. This satisfies the hunting objective of surfacing suspicious process-to-network chains, where a command shell launching PowerShell and beaconing externally indicates potential malicious activity.

Why this answer

The KQL query joins process creation events where `cmd.exe` is the parent and `powershell.exe` is the child with network events from the same device, filtering for outbound HTTPS (port 443) — this pattern identifies devices where a command shell spawned PowerShell that then made encrypted outbound connections, a common living-off-the-land technique. The join on DeviceId and time window is what ties the process chain to the network activity, which is the query's defining purpose.

Exam trap

SC-200 often tests whether candidates read the *join and filter* conditions rather than the surface process names — distractors like 'download files' or 'lateral movement' sound plausible but are not what the query's columns and port filter actually select for.

How to eliminate wrong answers

Option B is wrong because the query does not filter on file-download cmdlets (e.g., `Invoke-WebRequest`, `DownloadFile`) or file-write events — it only correlates process lineage with outbound connections. Option C is wrong because lateral movement detection would require remote service artifacts (SMB, WMI, PsExec, RDP) and authentication events, none of which appear in the query. Option D is wrong because integrity level is not referenced — the query does not filter on `IntegrityLevel` or token elevation, only on the parent-child process relationship and network port.

83
Multi-Selecthard

Which THREE approaches are effective for hunting threats in Microsoft Defender XDR using advanced hunting? (Choose three.)

Select 3 answers
A.Using known indicators of compromise (IOCs) from threat intelligence feeds.
B.Establishing a baseline of normal behavior and hunting for deviations.
C.Reviewing all alerts generated by automated detection rules.
D.Searching for any single event that appears unusual.
E.Applying machine learning models to detect anomalous patterns.
AnswersA, B, E

Using known IOCs such as malicious file hashes, suspicious domains, attacker IPs, and email sender addresses from threat intelligence feeds is effective because it gives the hunt concrete, evidence-backed starting points from both external intelligence and internal incident knowledge. In Microsoft Defender XDR, a hunter can run KQL queries over Advanced Hunting tables (DeviceFileEvents, DeviceNetworkEvents, EmailEvents, etc.) to cross-reference these IOCs and pivot to related processes, users, and machines. This method works best when the hunter expands beyond simple hash matches to hunt for subtle variations that preserve the attacker's underlying tradecraft.

Why this answer

Effective hunting in Microsoft Defender XDR using advanced hunting involves proactive approaches: using known IOCs from threat intelligence (A) helps identify known threats; establishing a baseline of normal behavior and hunting for deviations (B) detects anomalies; applying machine learning models (E) leverages automated anomaly detection. Option C is incorrect because reviewing all alerts is reactive and not a hunting technique. Option D is incorrect because hunting looks for patterns, not isolated unusual events.

84
MCQeasy

While threat hunting in Microsoft Sentinel, you want to create a hunting query that identifies all attempts to disable security controls. Which data table would be most appropriate to query for such activity?

A.Syslog
B.SecurityEvent
C.CommonSecurityLog
D.OfficeActivity
AnswerB

SecurityEvent captures Windows security auditing events, including modifications to security settings and attempts to disable controls such as Defender or audit policies. It is the appropriate table for hunting activity that weakens protective mechanisms across monitored machines.

Why this answer

The SecurityEvent table in Microsoft Sentinel contains Windows security events forwarded from agents, including Event ID 4688 (process creation) and events related to disabling security controls such as Windows Defender or audit policies. Threat hunting queries for control-disabling activity typically target SecurityEvent because it captures native Windows security log data. Other tables cover different log sources and would not contain these Windows security events.

Exam trap

The trap is confusing CommonSecurityLog (third-party CEF logs) with SecurityEvent (native Windows security logs); candidates often assume 'security' in the name means it holds all security events.

How to eliminate wrong answers

Option A is wrong because Syslog contains Linux/Unix syslog messages forwarded via the Log Analytics agent, not Windows Security event log entries. Option C is wrong because CommonSecurityLog holds CEF-formatted logs from third-party security appliances (firewalls, IDS/IPS), not native Windows security events. Option D is wrong because OfficeActivity contains Microsoft 365 audit logs (Exchange, SharePoint, Teams), which would not record local Windows security control changes.

85
MCQeasy

You are performing a threat hunt in Microsoft Sentinel. You want to identify devices that have been communicating with known malicious IP addresses. Which data source should you query?

A.SecurityEvent
B.CommonSecurityLog
C.DnsEvents
D.DeviceNetworkEvents
AnswerB

CommonSecurityLog is the Sentinel table that ingests normalized network traffic logs from firewalls and other security appliances using the Common Event Format (CEF). It records fields like source and destination IP addresses, ports, protocols, and the action taken (allow/deny), making it the go-to table for analyzing inter-host IP communication. For a hunt focused on direct network connections between two systems, this is the appropriate data source.

Why this answer

CommonSecurityLog is the correct data source because it aggregates logs from various security appliances (e.g., firewalls, proxies) using the Syslog or CEF format. These logs typically contain source and destination IP addresses, making them ideal for correlating internal devices with known malicious IPs during a threat hunt. SecurityEvent and DeviceNetworkEvents lack the necessary network-level IP communication data, while DnsEvents only logs DNS queries, not direct IP connections.

Exam trap

The trap here is that candidates often choose DnsEvents thinking DNS logs show all network communications, but they miss that DNS only resolves domain names to IPs and does not log the actual IP connections, which are captured in CommonSecurityLog from firewalls or proxies.

How to eliminate wrong answers

Option A is wrong because SecurityEvent collects Windows security audit logs (e.g., logon events, process creation) and does not include network communication records to external IPs. Option C is wrong because DnsEvents logs DNS query/response data (e.g., domain resolutions) but does not capture direct IP-to-IP communications with malicious addresses. Option D is wrong because DeviceNetworkEvents (from Microsoft Defender for Endpoint) records network connections on endpoints, but the question asks for a data source in Microsoft Sentinel, and CommonSecurityLog is the standard for aggregating firewall/proxy logs that show outbound connections to known bad IPs.

86
Multi-Selectmedium

Which TWO of the following are valid methods to initiate a threat hunting session in Microsoft Sentinel?

Select 2 answers
A.Create a custom analytics rule
B.Import a watchlist as a hunting query
C.Start from a specific detection rule
D.Use a predefined hunting query from the Microsoft Sentinel content hub
E.Enable live mode on a hunting query
AnswersC, D

Starting from a detection rule is a valid method because the rule's underlying KQL query exposes the same log data used for detection and can be run interactively in the Logs or Hunting blade to explore broader patterns. For example, you can right-click a rule, select 'Run query' to see its results, then refine the query to look for related activity. This pivot from a deterministic detection to a broader investigation is a recognized hunting entry point in Microsoft Sentinel.

Why this answer

Starting from a specific detection rule and using a predefined hunting query are both valid methods. Live mode is not a feature; custom analytics rules are for detection, not hunting; and watchlists are used for enrichment, not for initiating hunting.

87
Multi-Selecthard

Which THREE of the following are key considerations when designing a threat hunting program in Microsoft Defender XDR and Microsoft Sentinel? (Choose THREE.)

Select 3 answers
A.Understanding the data schema and available tables in the advanced hunting schema
B.Operational security (OpSec) to avoid tipping off adversaries during manual hunting
C.Implementing multi-factor authentication for all users
D.Using only built-in detection rules to identify threats
E.Data retention policies for logs in Microsoft Sentinel and Microsoft Defender XDR
AnswersA, B, E

A thorough understanding of the advanced hunting schema—including table names, column structure, and relationships—is essential for writing accurate and efficient KQL queries. Hunters must know, for example, that DeviceProcessEvents contains process creation data while IdentityLogonEvents holds authentication logs, and how to join these tables to trace lateral movement. Without this schema knowledge, analysts risk querying irrelevant tables, misinterpreting data, or missing critical evidence hidden in less obvious tables.

Why this answer

Option A is correct because effective threat hunting in Microsoft Defender XDR and Microsoft Sentinel requires knowing the advanced hunting schema — the exact table names (e.g., DeviceProcessEvents, DeviceNetworkEvents, EmailEvents, SigninLogs) and column/field types — so hunters can write precise KQL queries that surface relevant telemetry rather than guessing at data locations. Option B is correct because operational security (OpSec) matters during manual hunting: hunters must avoid actions that tip off adversaries, such as querying or interacting with compromised hosts in ways that generate detectable artifacts, since adversaries may monitor for reconnaissance and change their tactics, techniques, and procedures (TTPs) or go dormant. Option E is correct because data retention policies directly bound what a hunting program can investigate — Microsoft Sentinel's analytics and hunting queries can only search data within the configured retention period (interactive retention plus long-term retention tiers), and Defender XDR's advanced hunting is limited to its own retention window (typically 30 days), so retention must be planned to support historical hunting and incident reconstruction.

Option C is not correct here because, while MFA is a critical identity security control, it is a general security hardening measure rather than a specific design consideration for a threat hunting program. Option D is not correct because relying only on built-in detection rules contradicts the purpose of threat hunting, which is proactive, hypothesis-driven investigation beyond automated detections; hunters use custom KQL queries, not just out-of-the-box rules.

Exam trap

The trap is selecting general security controls like MFA as part of threat hunting design. Candidates must distinguish between foundational security hygiene and specific threat hunting program considerations.

88
MCQmedium

While hunting in Microsoft Sentinel, you find a KQL query that uses the `evaluate` operator with `bag_unpack` to expand JSON properties. The query runs slowly and times out. What is the best practice to optimize this query?

A.Increase the cluster's concurrency and nodes.
B.Remove the `evaluate` operator and use `extend` with `parse_json`.
C.Add a `where` clause to filter rows before applying `bag_unpack`.
D.Use the `materialize` function to cache the entire table before expansion.
AnswerC

Placing a `where` clause before `bag_unpack` reduces the number of rows entering the expansion, which is the most direct way to cut the CPU and memory cost of unpacking. Filtering on a non-computed column (or an indexed field) lets the engine prune data early, so `bag_unpack` operates on a minimal logical set and the query's overall runtime drops substantially.

Why this answer

The best practice for optimizing KQL queries that use bag_unpack is to filter rows with a where clause before applying the expansion. bag_unpack is expensive because it dynamically expands JSON properties into columns, so reducing the row set first minimizes the work. This is the correct optimization because it addresses the root cause: processing too many rows through an expensive operator.

Exam trap

SC-200 often tests the principle of filtering before expensive operators — candidates incorrectly choose scaling or materialize instead of reducing input rows before bag_unpack.

How to eliminate wrong answers

Option A is wrong because increasing cluster concurrency and nodes is a scaling action, not a query optimization; it may mask inefficiency but does not fix the query. Option B is wrong because replacing evaluate bag_unpack with extend parse_json is not equivalent — parse_json alone does not expand JSON into columns and may not improve performance. Option D is wrong because materialize caches intermediate results but does not reduce the cost of expanding a large table; it can even increase memory usage.

89
MCQhard

A threat hunter is analyzing a potential advanced persistent threat (APT) that uses living-off-the-land binaries (LOLBins) like certutil.exe to download payloads. The hunter wants to find instances where certutil.exe was used to download files from the internet in the last week. Which KQL query in Microsoft Sentinel would be most effective?

A.DeviceProcessEvents | where TimeGenerated > ago(7d) | where FileName == "powershell.exe" | where ProcessCommandLine contains "-enc" | project Timestamp, DeviceName, ProcessCommandLine
B.DeviceProcessEvents | where TimeGenerated > ago(7d) | where FileName == "mshta.exe" | where ProcessCommandLine contains "http" | project Timestamp, DeviceName, ProcessCommandLine
C.DeviceProcessEvents | where TimeGenerated > ago(7d) | where FileName == "certutil.exe" | where ProcessCommandLine contains "-urlcache" or ProcessCommandLine contains "-split" | project Timestamp, DeviceName, ProcessCommandLine
D.DeviceProcessEvents | where TimeGenerated > ago(7d) | where FileName == "wscript.exe" | where ProcessCommandLine contains "http" | project Timestamp, DeviceName, ProcessCommandLine
AnswerC

DeviceProcessEvents captures process creation telemetry from Defender for Endpoint, so filtering FileName for certutil.exe and ProcessCommandLine for the -urlcache or -split switches isolates exactly the LOLBin download behaviour the hunter hypothesised, within the required seven-day window.

Why this answer

The query in option C correctly targets certutil.exe and filters for the specific command-line arguments '-urlcache' and '-split', which are commonly used by attackers to download files from the internet. This directly addresses the threat hunter's goal of finding certutil.exe download activity. The other options focus on different LOLBins (powershell.exe, mshta.exe, wscript.exe) that are not mentioned in the scenario.

Exam trap

SC-200 often tests the ability to distinguish between different LOLBins and their command-line arguments. Candidates might pick a query for a different LOLBin due to familiarity, but the question specifically mentions certutil.exe.

How to eliminate wrong answers

Option A is wrong because it looks for powershell.exe with encoded commands, not certutil.exe downloads. Option B is wrong because it targets mshta.exe, another LOLBin, but not the one specified. Option D is wrong because it targets wscript.exe, which is also not certutil.exe.

90
MCQhard

You are a threat hunter for a company that uses Microsoft Defender for Endpoint (now part of Microsoft Defender XDR). You need to investigate a potential privilege escalation attack. You have collected process creation events from endpoints and want to identify instances where a process with low integrity level spawned a process with high integrity level. The DeviceProcessEvents table includes fields: DeviceName, AccountName, InitiatingProcessFileName, InitiatingProcessIntegrityLevel, ProcessFileName, ProcessIntegrityLevel. You need to write an advanced hunting query that returns the top 10 devices where this escalation occurred most frequently in the last 7 days. Which query should you use?

A.DeviceProcessEvents | where Timestamp > ago(7d) | where InitiatingProcessIntegrityLevel == "Low" and ProcessIntegrityLevel == "High" | summarize count() by DeviceName | top 10 by count_
B.DeviceProcessEvents | where Timestamp > ago(7d) | where InitiatingProcessIntegrityLevel == "Medium" and ProcessIntegrityLevel == "High" | summarize count() by DeviceName | top 10 by count_
C.DeviceProcessEvents | where Timestamp > ago(7d) | where InitiatingProcessIntegrityLevel != ProcessIntegrityLevel | summarize count() by DeviceName | top 10 by count_
D.DeviceProcessEvents | where Timestamp > ago(7d) | where InitiatingProcessFileName != ProcessFileName | summarize count() by DeviceName | top 10 by count_
AnswerA

Filtering on InitiatingProcessIntegrityLevel "Low" and ProcessIntegrityLevel "High" isolates genuine low-to-high integrity transitions, the exact escalation pattern sought. Summarising count() by DeviceName then top 10 by count_ ranks the noisiest endpoints over the ago(7d) window, matching both the frequency and timeframe constraints.

Why this answer

The query must filter for a genuine privilege escalation, which in Windows integrity-level terms means a low-integrity process spawning a high-integrity process. Option A correctly compares InitiatingProcessIntegrityLevel == "Low" against ProcessIntegrityLevel == "High", then aggregates by DeviceName and uses top 10 by count_ to surface the devices with the most escalation events in the last 7 days. This matches the stated requirement exactly.

Exam trap

SC-200 often tests whether candidates confuse integrity-level escalation (Low to High) with any integrity-level change or with user privilege elevation, causing them to pick the != or Medium-to-High filter.

How to eliminate wrong answers

Option B is wrong because Medium-to-High is a normal, expected transition (e.g., a user-launched process spawning an elevated process) and does not represent the low-to-high escalation the hunter was asked to find. Option C is wrong because != simply finds any integrity-level change, including legitimate de-escalations (High to Low) and Medium-to-Low transitions, producing massive false positives rather than privilege escalation. Option D is wrong because comparing process file names has nothing to do with integrity levels; different executables are spawned constantly during normal operation and this filter would return irrelevant noise.

91
Multi-Selecteasy

Which TWO of the following are recommended practices when performing threat hunting in Microsoft Sentinel? (Choose 2)

Select 2 answers
A.Create custom hunting queries based on hypothesis
B.Rely solely on automated detection rules
C.Disable all built-in analytics rules to avoid noise
D.Delete log data older than 30 days to improve query performance
E.Use watchlists to maintain high-value indicators for matching
AnswersA, E

Threat hunting is hypothesis-driven: analysts form a theory about adversary behaviour, then encode it as a custom query to surface matching activity. This satisfies the recommended practise of proactive, hypothesis-led hunting rather than relying solely on existing scheduled detections.

Why this answer

Option A is correct because threat hunting in Microsoft Sentinel is hypothesis-driven: analysts write custom hunting queries in KQL (via the Hunting blade or Logs) to proactively search for evidence of the hypothesized adversary behavior rather than waiting for alerts. Option E is correct because watchlists let you upload and manage lists of high-value indicators (IPs, accounts, hashes, domains) that hunting queries can join against using the _GetWatchlist() function, keeping threat intel current without editing each query. Option B is wrong because relying solely on automated analytics rules is reactive detection, not proactive hunting, and misses threats the rules do not cover.

Option C is wrong because disabling all built-in analytics rules removes valuable detections and creates blind spots instead of tuning noise. Option D is wrong because deleting log data destroys the historical evidence hunting depends on and undermines retention/compliance; query performance is addressed with table plans, summaries, and scoping, not data deletion.

Exam trap

The trap is picking 'rely on automated detections' or 'disable noisy rules' — both sound operationally convenient but contradict the proactive, hypothesis-driven nature of threat hunting.

92
MCQhard

Refer to the exhibit. An analyst is reviewing a custom detection rule in Microsoft Sentinel. The rule is triggering many false positives from legitimate remote desktop connections. What should the analyst do to reduce false positives while keeping detection of pass-the-hash attacks?

A.Change the data source from SecurityEvent to Event.
B.Remove the AuthenticationPackage filter to include all packages.
C.Change LogonType to 10 to target remote interactive logons.
D.Add an exclusion for known administrative jump boxes.
AnswerD

Excluding known administrative jump boxes suppresses alerts from trusted sources performing legitimate RDP, while the rule's pass-the-hash logic still fires on anomalous authentication patterns elsewhere. This targets the false-positive source named in the stem without weakening detection coverage.

Why this answer

The rule detects pass-the-hash attacks by looking for suspicious logon patterns (e.g., LogonType 3 with NTLM authentication). Legitimate remote desktop connections from known administrative jump boxes are a common source of false positives. Adding an exclusion for these trusted IPs or hostnames allows the rule to continue detecting pass-the-hash attempts from other sources while suppressing noise from authorized administrative activity.

This is a standard tuning technique in Microsoft Sentinel to improve signal-to-noise ratio without weakening detection coverage.

Exam trap

SC-200 often tests the misconception that changing logon types or data sources can reduce false positives, when in fact targeted exclusions of known legitimate activity are the correct tuning approach.

How to eliminate wrong answers

Option A is wrong because changing the data source from SecurityEvent to Event would not reduce false positives; it would likely break the rule entirely since Event is a generic table that may not contain the necessary security event details (e.g., LogonType, AuthenticationPackage) required for pass-the-hash detection. Option B is wrong because removing the AuthenticationPackage filter would broaden the rule to include all authentication packages, increasing false positives rather than reducing them, as it would capture more legitimate logons. Option C is wrong because changing LogonType to 10 (RemoteInteractive) would target remote desktop logons specifically, but pass-the-hash attacks often use network logons (LogonType 3), so this would miss the actual attacks and not address the false positives from legitimate RDP connections.

93
Multi-Selectmedium

Which THREE techniques are commonly used in Microsoft Sentinel threat hunting to identify command and control (C2) communication? (Select THREE.)

Select 3 answers
A.Analyzing email headers for phishing
B.Detecting DNS tunneling
C.Analyzing network beaconing patterns
D.Examining SSL/TLS certificate anomalies
E.Identifying brute force attempts
AnswersB, C, D

Detecting DNS tunnelling is crucial for identifying C2 communication because attackers frequently encapsulate malicious traffic within legitimate DNS queries and responses. Microsoft Sentinel can analyse DNS logs, looking for anomalous patterns such as excessively long domain names, unusual query frequencies, or specific data encoding within DNS records. This technique effectively uncovers covert C2 channels, satisfying the requirement to identify command and control communication.

Why this answer

Detecting DNS tunneling (B) is correct because attackers frequently encode C2 data inside DNS queries and responses, and Sentinel hunting queries can flag anomalies such as high-entropy subdomains, excessive TXT/NULL record requests, or unusually long query names in DNS events. Analyzing network beaconing patterns (C) is correct because C2 implants typically check in at regular intervals, so hunting for periodic, low-volume outbound connections (for example, consistent time deltas or repeated small byte counts to the same destination) helps reveal compromised hosts. Examining SSL/TLS certificate anomalies (D) is correct because malicious C2 infrastructure often uses self-signed, expired, mismatched, or otherwise suspicious certificates, and Sentinel can correlate certificate metadata from network logs to identify such traffic.

Analyzing email headers for phishing (A) is not a C2 communication technique; it targets initial access via email, and identifying brute force attempts (E) addresses credential attacks rather than command-and-control traffic.

Exam trap

SC-200 often tests whether candidates can distinguish C2 detection techniques (DNS tunneling, beaconing, TLS anomalies) from adjacent attack-stage techniques like phishing analysis or brute force detection.

94
MCQhard

You are hunting for signs of Kerberoasting in Microsoft Sentinel. Which hunting query using KQL would you use to identify service principal names (SPNs) being queried via Kerberos TGS requests?

A.SecurityEvent | where EventID == 4769 and TicketEncryptionType == 0x17
B.DeviceEvents | where ActionType == 'KerberosTicketRequest'
C.DeviceLogonEvents | where LogonType == 'Kerberos' and AccountDomain == 'Service'
D.SecurityEvent | where EventID == 4768 and TicketEncryptionType == 0x17
AnswerA

Event ID 4769 logs Kerberos service ticket (TGS) requests, and encryption type 0x17 (RC4-HMAC) reveals weak cipher use typical of Kerberoasting, where attackers request SPN tickets then crack them offline. Filtering both fields surfaces exactly the SPN queries the stem requires.

Why this answer

Kerberoasting involves requesting TGS tickets for Service Principal Names (SPNs). In Microsoft Sentinel, the SecurityEvent table with EventID 4769 logs TGS requests. TicketEncryptionType 0x17 indicates RC4 encryption, which is commonly used in Kerberoasting attacks.

Option A correctly identifies this query. Option D is incorrect because EventID 4768 is for TGT requests, not TGS. Option B (DeviceEvents) may not capture this specific event, and Option C (DeviceLogonEvents) does not focus on SPN details.

95
MCQhard

You are analyzing the query above in Microsoft 365 Defender advanced hunting. The goal is to identify potentially compromised accounts used only once. The query returns thousands of results including many normal single logons. How can you refine the query to reduce false positives?

A.Change the where clause to LogonCount > 1.
B.Remove the filter on AccountUpn endswith "@contoso.com".
C.Add a filter to only include accounts that have never logged on before.
D.Add a filter to exclude IP addresses from the corporate VPN range and common applications like Outlook Web Access.
AnswerD

Filtering out known-benign sources — corporate VPN egress addresses and common applications like Outlook Web Access — removes expected single logons, leaving anomalous ones. This directly targets the false-positive constraint by narrowing results to genuinely suspicious single-use accounts.

Why this answer

Adding a filter to exclude IP addresses from the corporate VPN range and common applications (like Outlook Web Access) helps reduce false positives by removing legitimate single logons that are expected. Option A (LogonCount > 1) would exclude the very accounts we are trying to find (single logons). Option B (removing the domain filter) would expand results but not necessarily reduce false positives.

Option C (accounts never logged on before) is too restrictive and may miss compromised accounts used only once.

96
Multi-Selecteasy

Which TWO of the following are common techniques used by attackers to bypass security controls that a threat hunter should look for?

Select 2 answers
A.Process injection into trusted processes
B.Enabling multi-factor authentication
C.Regular software updates
D.Enforcing strong password policies
E.DLL sideloading
AnswersA, E

Process injection writes malicious code into a trusted process's address space, so activity inherits that process's legitimacy and evades allow-listing and behavioural controls. Threat hunters detect it via anomalous memory allocation, thread creation or unexpected module loads.

Why this answer

Process injection into trusted processes (A) is a classic defense-evasion technique where an attacker writes malicious code into the memory space of a legitimate, trusted process (e.g., via CreateRemoteThread, APC injection, or process hollowing), allowing the payload to inherit the host process's privileges and blend into normal activity, which is exactly the kind of control bypass a threat hunter should detect. DLL sideloading (E) is another common evasion method in which a legitimate executable loads a malicious DLL from an attacker-controlled location due to insecure search-order or path resolution, hijacking trusted execution flow without triggering obvious alerts. By contrast, enabling multi-factor authentication (B), applying regular software updates (C), and enforcing strong password policies (D) are defensive hardening measures that strengthen security controls rather than techniques used to bypass them, so they are not attacker evasion methods.

97
MCQhard

You are hunting for lateral movement in your environment. In Microsoft Defender for Identity, which activity is a strong indicator of a potential pass-the-hash attack?

A.A user logging on with a smart card.
B.An NTLM authentication originating from a machine that is not the user's usual machine.
C.A remote desktop connection from a non-admin workstation to a domain controller.
D.A service account logging on to multiple servers simultaneously.
AnswerB

NTLM authentication originating from a machine the user does not normally use is a strong lateral movement indicator because NTLM uses a password hash in a challenge-response protocol, and attackers often employ pass-the-hash techniques to authenticate from a compromised host. In a Windows environment, this would appear as Event ID 4624 with LogonType 3 and NTLM as the authentication package, combined with a source hostname or IP that violates the user's typical logon pattern. This aligns with stolen credentials or hash theft, as a legitimate user would almost always authenticate from their known workstations or VPN exit points, so an unexpected source machine is statistically suspicious.

Why this answer

Pass-the-hash attacks involve using a captured NTLM hash to authenticate without knowing the plaintext password. In Defender for Identity, a strong indicator is NTLM authentication originating from a machine that is not the user's usual machine, because the attacker is moving laterally using the hash from a compromised host. This behavior is flagged as suspicious because it deviates from normal user logon patterns.

Exam trap

SC-200 often tests the specific indicators of pass-the-hash, and candidates may confuse it with other suspicious activities like service account logons or smart card usage. The trap is selecting a common but non-specific event instead of the NTLM authentication from an unusual machine.

How to eliminate wrong answers

Option A is wrong because smart card logons use certificate-based authentication (PKINIT) and are not associated with pass-the-hash attacks. Option C is wrong because a remote desktop connection from a non-admin workstation to a domain controller is a common administrative activity and not a specific indicator of pass-the-hash. Option D is wrong because service accounts logging on to multiple servers simultaneously is typical for service accounts and does not specifically indicate pass-the-hash.

98
MCQeasy

Which Microsoft Sentinel feature allows you to query data across multiple workspaces in a single KQL query?

A.The union operator with workspace names
B.The externaldata operator with workspace URLs
C.The workspace() function in KQL
D.The join operator with workspace identifiers
AnswerC

The workspace() function is a KQL table-scoping function that accepts a workspace name or resource ID and returns a table reference for that workspace, allowing cross-workspace queries in a single KQL statement. In Microsoft Sentinel, analysts commonly use workspace() with the union operator to combine security tables from multiple workspaces, for example: union workspace("sentinel-ws1").SecurityEvent, workspace("sentinel-ws2").SecurityEvent. This is the correct feature because it is purpose-built to reference other Log Analytics workspaces from within your query.

Why this answer

The workspace() function in KQL is specifically designed to reference a workspace by its identifier, allowing a single query to pull tables from multiple Microsoft Sentinel workspaces (or Log Analytics workspaces) without leaving the current query context. It is the documented cross-workspace query mechanism in Sentinel, and it can be combined with union to aggregate results across workspaces.

Exam trap

SC-200 often tests whether candidates confuse KQL operators (union, join, externaldata) with the workspace() function that actually provides cross-workspace scope — the trap is assuming union or join can name a workspace directly.

How to eliminate wrong answers

Option A is wrong because the union operator alone cannot resolve workspace names — it only combines result sets from tables/functions already in scope; you still need workspace() to reference the remote workspace. Option B is wrong because externaldata is used to pull data from external storage URIs (blobs, files) into a query, not to query another Sentinel/Log Analytics workspace. Option D is wrong because join is a row-combining operator that requires both sides to already be resolvable tables; it does not provide any cross-workspace resolution capability on its own.

99
MCQeasy

A security analyst is using KQL in Microsoft Sentinel to hunt for potential data exfiltration by a user who has been sending unusually large amounts of data to an external IP address. Which KQL operator should the analyst use to identify the top source IP addresses and total bytes sent over the last 7 days?

A.... | where SentBytes > 1000000 | project SourceIP, SentBytes
B.... | extend TotalBytes=SentBytes | summarize count() by SourceIP
C.... | project SourceIP, SentBytes | sort by SentBytes desc
D.... | summarize TotalBytes=sum(SentBytes) by SourceIP | top 10 by TotalBytes desc
AnswerD

This is the correct approach because the summarize operator groups all events by SourceIP and calculates TotalBytes as the sum of SentBytes for each group, converting row-level byte counts into a single aggregate metric per unique IP address. The subsequent top 10 by TotalBytes desc operator then sorts those aggregated results in descending order and returns only the first ten rows, which are the ten source IPs with the highest total outbound byte volume. Using 'top' after 'summarize' is also more efficient than 'sort' followed by 'take' because Kusto can discard non-top records during execution. This pipeline precisely satisfies the goal of identifying the top source IPs by total bytes sent and is the only option that combines both grouping and aggregation with a limiting operation.

Why this answer

To identify the top source IPs by total bytes sent over 7 days, the analyst needs to aggregate bytes per source IP and then rank them. `summarize TotalBytes=sum(SentBytes) by SourceIP | top 10 by TotalBytes desc` does exactly that: it sums SentBytes grouped by SourceIP and returns the top 10 by total bytes, which is the correct KQL pattern for this hunt.

Exam trap

SC-200 often tests whether candidates confuse `count()` with `sum()` in `summarize`, or use `project`/`sort` on raw rows instead of aggregating first — the exam wants the aggregation-then-rank pattern.

How to eliminate wrong answers

Option A is wrong because `where SentBytes > 1000000 | project SourceIP, SentBytes` only filters and projects individual rows — it does not aggregate total bytes per source IP, so it cannot show the top senders. Option B is wrong because `summarize count() by SourceIP` counts the number of events per source IP, not the total bytes sent, so it answers a different question. Option C is wrong because `project SourceIP, SentBytes | sort by SentBytes desc` sorts individual events, not aggregated totals, and does not limit to the top 10 source IPs by summed bytes.

100
Multi-Selecthard

Which TWO of the following are key indicators of a potential DCSync attack that a threat hunter should look for in Microsoft Sentinel? (Select two.)

Select 2 answers
A.Failed logon attempts from a single IP
B.A new user account created with domain admin privileges
C.Event ID 4662 with access mask for DS-Replication-Get-Changes
D.Multiple Kerberos ticket requests from a single user
E.Directory replication requests from non-domain controller accounts
AnswersC, E

Event ID 4662 with the DS-Replication-Get-Changes access mask directly satisfies the stem's replication-permission indicator: DCSync abuses directory replication rights to harvest credential hashes. Monitoring this in Microsoft Sentinel detects non-domain-controller accounts requesting replication, the defining anomaly of DCSync activity.

Why this answer

Option C is correct because DCSync abuse is detected through Windows Security Event ID 4662, which records access to Active Directory objects; the telltale sign is an access mask containing the DS-Replication-Get-Changes (and often DS-Replication-Get-Changes-All) control access right on the domain object, indicating replication data was requested. Option E is correct because legitimate directory replication is performed only by domain controllers, so replication requests (the same 4662/DS-Replication rights, or DRSUAPI replication traffic) originating from non-domain-controller accounts or workstations strongly indicate a DCSync attack using tools like Mimikatz or Impacket's secretsdump. Option A does not belong because failed logons from one IP indicate brute-force or password-spray activity, not replication abuse.

Option B does not belong because creating a domain-admin account is a persistence or privilege-escalation action, not the replication-rights access pattern characteristic of DCSync. Option D does not belong because multiple Kerberos ticket requests suggest Kerberoasting or ticket harvesting, which is unrelated to the DS-Replication-Get-Changes access that defines DCSync.

101
MCQmedium

You are investigating a potential data exfiltration using Microsoft Defender for Cloud Apps. You find that a user downloaded a large number of files from SharePoint Online to a personal device. Which anomaly detection policy type would have detected this?

A.Activity anomaly detection policy
B.File anomaly detection policy
C.Cloud Discovery anomaly detection policy
D.OAuth app anomaly detection policy
AnswerA

Activity anomaly detection policies in Microsoft Defender for Cloud Apps baseline each user's typical file download volume and alert when behaviour deviates sharply. A mass SharePoint Online download to a personal device exceeds that learned baseline, matching the exfiltration scenario precisely.

Why this answer

Activity anomaly detection policies detect unusual download volumes. Option B is wrong because File anomaly policies focus on file types and metadata. Option C is wrong because Cloud Discovery anomaly policies focus on shadow IT.

Option D is wrong because OAuth app anomaly policies focus on app permissions.

102
MCQhard

In a threat hunt, you discover that a non-admin user account created a scheduled task that executes a PowerShell script to connect to an external IP on port 4444. Which of the following is the most likely interpretation of this activity?

A.The user is performing legitimate remote administration
B.The PowerShell script is a remote assistance tool
C.The scheduled task is part of a software update mechanism
D.The scheduled task is likely a reverse shell for persistence and remote access
AnswerD

A scheduled task that invokes PowerShell to establish an outbound connection to an external IP on port 4444 is a textbook reverse shell persistence mechanism. The attacker creates the scheduled task to execute at logon or on a recurring interval, ensuring reliable command-and-control access even after system reboots. PowerShell is frequently abused for this purpose because it enables 'living off the land' fileless attacks, often using System.Net.Sockets.TcpClient to send shell output without writing scripts to disk. Port 4444 is also a common default listener for Metasploit, and the non-admin context suggests the attacker is operating with limited privileges, possibly after phishing or lateral movement, maintaining access while working to elevate privileges.

Why this answer

A non-admin user creating a scheduled task that runs PowerShell to connect to an external IP on port 4444 is a textbook reverse shell pattern. Port 4444 is the default listener port for Metasploit's meterpreter payload, and scheduled tasks provide persistence across reboots. The combination of non-admin context, external IP, unusual port, and scheduled execution strongly indicates attacker persistence and command-and-control.

Exam trap

SC-200 often tests whether candidates can distinguish benign admin activity from attacker tradecraft — the trap is assuming 'scheduled task' or 'PowerShell' is inherently benign and missing the reverse-shell indicators (non-admin, external IP, port 4444).

How to eliminate wrong answers

Option A is wrong because legitimate remote administration is typically performed by admin accounts using sanctioned tools (RDP, WinRM, SSH) with documented change control, not by non-admin users via scheduled PowerShell to arbitrary external IPs. Option B is wrong because remote assistance tools (Quick Assist, TeamViewer) use vendor-specific signed binaries and known ports, not raw PowerShell connecting to port 4444. Option C is wrong because software update mechanisms use signed installers, WSUS/SCCM, or vendor endpoints over HTTPS (443), not PowerShell reverse connections to arbitrary IPs on port 4444.

103
MCQmedium

You are reviewing a threat hunting KQL query in Microsoft Sentinel. The query references an external CSV containing malicious IPs. The query returns no results despite known malicious activity. What is the most likely issue?

A.The externaldata function is not supported in Microsoft Sentinel.
B.The HuntingTimeRange variable is not being used correctly.
C.The project clause removes the RemoteIP column.
D.The external CSV file is not accessible or the URL is malformed.
AnswerD

When a KQL query uses `externaldata` to load a CSV file and then performs a `join` against that data, the join depends entirely on the availability and format of the external file. If the URL is malformed (e.g., missing scheme, incorrect path, invalid SAS token) or the endpoint is inaccessible (e.g., network restrictions, expired token, or file deleted), `externaldata` returns an empty table. The subsequent `join` then finds no matching rows, silently producing an empty result set, which matches the symptom described in the question.

Why this answer

The query uses the externaldata operator to load an external CSV file. If the file URL is malformed or inaccessible, the query will not load any IPs, resulting in no matches. Option A is incorrect because externaldata is supported in Microsoft Sentinel.

Option B is incorrect because the HuntingTimeRange variable is likely used correctly to filter by time, but time filtering is not the cause of zero results. Option C is incorrect because the project clause selects the RemoteIP column; it does not remove it.

104
MCQmedium

You are a threat hunter in a Microsoft Sentinel environment that ingests both Microsoft Defender XDR and third-party network logs. You want to build a reusable hunting query that surfaces failed authentication attempts from IP addresses that have never before been associated with successful sign-ins in your tenant. Which KQL operator should you use to correlate the two datasets and return only the novel source IPs?

A.union of SigninLogs and the successful sign-in set
B.summarize count() by IPAddress on SigninLogs only
C.leftanti join between SigninLogs and the successful sign-in set
D.inner join between SigninLogs and the successful sign-in set
AnswerC

A leftanti join returns rows from the left table that have no match in the right table. By joining failed sign-in records against the historical successful sign-in IP set, you get exactly the source IPs with failures but no prior success, which is the novel-IP condition the hunt requires.

Why this answer

The hunt hypothesis depends on identifying source IPs that generate failures but have no history of successful authentication. A leftanti join preserves the left-side failed sign-in rows and drops any whose IP key appears in the right-side success set, yielding the novel addresses the analyst wants to investigate further.

Exam trap

The trap here is assuming an inner join is needed to correlate datasets, when the requirement is to exclude known-good IPs and only a leftanti join preserves unmatched left-side rows.

105
MCQeasy

You are a threat hunter in Microsoft Sentinel. You want to identify all devices that have communicated with a known malicious IP address (e.g., 203.0.113.5) over the past week. Which data source should you query to find network connection events?

A.DeviceNetworkEvents
B.AzureNetworkAnalytics_CL
C.CommonSecurityLog
D.Syslog
AnswerA

DeviceNetworkEvents in Microsoft Defender XDR (ingested into Microsoft Sentinel via the Defender XDR connector) provides detailed network connection events from endpoints, including remote IP addresses. Querying this table for the malicious IP will identify all devices that connected to it, directly fulfilling the hunting requirement.

Why this answer

DeviceNetworkEvents is the correct data source because it captures endpoint network connections, including remote IP addresses, and is available in Microsoft Sentinel through the Microsoft Defender XDR connector. Querying it for the malicious IP will reveal all devices that communicated with it. Other sources like CommonSecurityLog or Syslog may have some network data but are not as comprehensive or endpoint-focused.

Exam trap

The trap here is assuming that any network log source, such as CommonSecurityLog or AzureNetworkAnalytics_CL, will provide complete endpoint connection data, when only DeviceNetworkEvents offers the necessary endpoint-centric network telemetry.

106
MCQhard

While threat hunting, you find a suspicious scheduled task that runs a PowerShell script from a temp directory. You want to check if this task exists on other devices in the environment. Which Microsoft Defender for Endpoint advanced hunting table would you query?

A.DeviceProcessEvents
B.DeviceNetworkEvents
C.DeviceEvents
D.DeviceRegistryEvents
AnswerC

DeviceEvents records scheduled task creation and related process activity, including the task's action and initiating command line. Querying it surfaces matching PowerShell-from-temp-directory tasks across enrolled devices, letting you determine whether the suspicious task exists elsewhere in the estate.

Why this answer

The `DeviceEvents` table includes scheduled task creation events (ActionType: ScheduledTaskCreated). Option A is wrong because `DeviceProcessEvents` focuses on process execution, not task creation. Option B is wrong because `DeviceNetworkEvents` is for network connections.

Option D is wrong because `DeviceRegistryEvents` is for registry changes.

107
MCQeasy

As a threat hunter, you want to use MITRE ATT&CK techniques to categorize detected behaviors. In Microsoft Sentinel, which feature allows you to map alerts to MITRE techniques automatically?

A.Analytics rules
B.Playbooks
C.Watchlists
D.Workbooks
AnswerA

Analytics rules in Microsoft Sentinel include a MITRE ATT&CK mapping section where each rule's tactics and techniques are configured. When the rule fires, generated incidents and alerts inherit those technique tags automatically, satisfying the requirement to categorise detected behaviours without manual enrichment.

Why this answer

Analytics rules in Microsoft Sentinel allow you to map alerts to MITRE ATT&CK techniques automatically. When creating or editing an analytics rule, you can select the relevant MITRE ATT&CK tactic and technique, which enriches the alert with threat intelligence context. Workbooks (Option D) are for visualization, not mapping.

Playbooks (Option B) are for automated response. Watchlists (Option C) are for reference data. Therefore, Option A is correct.

108
MCQeasy

A threat hunter wants to identify all devices that have communicated with a known malicious IP address in the last 7 days. Which table in Microsoft Defender for Endpoint advanced hunting should be queried?

A.DeviceFileEvents
B.DeviceNetworkEvents
C.DeviceProcessEvents
D.DeviceRegistryEvents
AnswerB

DeviceNetworkEvents is the Advanced Hunting table that stores network connection activity initiated by processes, including source and destination IP addresses, remote ports, protocols, and connection metadata. A threat hunter can query this table with a known-bad IP or domain to list every device that established such communication. This makes it the direct and authoritative source for identifying compromised or suspicious endpoints.

Why this answer

The DeviceNetworkEvents table in Microsoft Defender for Endpoint advanced hunting contains information about network connections, including remote IP addresses and ports. To identify devices that communicated with a specific malicious IP, querying this table for the RemoteIP field is the correct approach. It captures both inbound and outbound network traffic events.

Exam trap

SC-200 often tests knowledge of the advanced hunting schema, and candidates may confuse network events with process or file events, leading to incorrect table selection.

How to eliminate wrong answers

Option A is wrong because DeviceFileEvents records file creation, modification, and other file system activities, not network communications. Option C is wrong because DeviceProcessEvents logs process creation and related events, not network connections. Option D is wrong because DeviceRegistryEvents tracks registry key modifications, which are unrelated to network traffic.

109
Multi-Selectmedium

Which TWO of the following are effective techniques for identifying lateral movement in Microsoft Defender for Endpoint advanced hunting? (Choose two.)

Select 2 answers
A.Check for successful logons from public IP addresses
B.Look for large file uploads to cloud storage
C.Search for remote desktop connections from non-administrative workstations
D.Monitor for phishing emails
E.Analyze NTLM authentication events for pass-the-hash
AnswersC, E

Unexpected remote desktop connections from non-administrative workstations are a strong lateral movement indicator because attackers frequently use RDP to hop to other systems once they compromise an endpoint. By searching for RDP sessions initiated from a standard user's workstation, a defender can spot activity that does not match the user's baseline behavior, especially when the destination is a server or privileged host. This technique corresponds to MITRE ATT&CK T1021.001, since legitimate users rarely initiate such connections from non-admin workstations.

Why this answer

Option C is correct because in Microsoft Defender for Endpoint advanced hunting, RDP logons (e.g., LogonType 10 in DeviceLogonEvents) originating from non-administrative workstations are a classic lateral-movement indicator, since attackers pivot from a compromised user endpoint to other hosts rather than from trusted admin jump boxes. Option E is correct because NTLM authentication events (e.g., in DeviceLogonEvents or DeviceEvents with NTLM-related fields) can reveal pass-the-hash activity, where stolen NTLM hashes are reused to authenticate to remote systems without knowing the plaintext password, a hallmark of lateral movement. Option A is not the best fit because successful logons from public IP addresses typically indicate initial access or external exposure rather than internal lateral movement.

Option B is unrelated because large uploads to cloud storage suggest exfiltration, not lateral movement. Option D is unrelated because phishing emails are an initial-access vector, not a lateral-movement detection technique in advanced hunting.

Exam trap

SC-200 often tests whether candidates can distinguish lateral movement from initial access and exfiltration — options about phishing or cloud uploads are distractors that describe other attack stages.

110
MCQhard

You are reviewing a custom hunting query in Microsoft Sentinel. The query above returns results, but you suspect it misses low-frequency beaconing. Which modification improves detection while reducing false positives?

A.Use a sliding window to count distinct connection times per IP per device
B.Group by DeviceName only
C.Decrease the count threshold to 10
D.Add RemotePort to the summarize clause
AnswerA

Grouping connections into a sliding window and counting distinct connection times per IP and device surfaces periodic low-and-slow beaconing that single-event thresholds miss, while the distinct-count aggregation suppresses noisy repeated hits from the same host, cutting false positives.

Why this answer

Low-frequency beaconing is characterized by a small number of connections spread over long, regular intervals — a simple count threshold misses it because the total count is low. Using a sliding window (e.g., bin() or make-series with a time window) to count distinct connection times per remote IP per device surfaces the periodicity and regularity that distinguishes beaconing from normal traffic, while grouping by both IP and device reduces false positives from benign recurring connections.

Exam trap

SC-200 often tests the misconception that lowering a count threshold improves beaconing detection — candidates confuse 'more sensitive' with 'more accurate' and ignore that beaconing is defined by timing regularity, not volume.

How to eliminate wrong answers

Option B is wrong because grouping by DeviceName only collapses all remote IPs into one bucket, hiding the per-IP beaconing pattern and increasing false positives from unrelated traffic. Option C is wrong because decreasing the count threshold to 10 makes the query more sensitive to any low-volume traffic, dramatically increasing false positives without addressing the periodicity that defines beaconing. Option D is wrong because adding RemotePort to the summarize clause fragments the data further and does not help detect regularity — beaconing is identified by timing patterns, not port diversity.

111
MCQmedium

Your organization uses Microsoft Sentinel with the Microsoft Defender XDR connector to ingest alerts and incidents from Defender for Endpoint, Defender for Office 365, and Defender for Identity. As a threat hunter, you want to proactively search for devices that may be communicating with known malicious IP addresses that have not yet triggered an alert. You have a list of known malicious IP addresses from an external threat intelligence feed. Which approach should you take to perform this hunt efficiently?

A.Create a Logic App that runs hourly and checks each IP against DeviceNetworkEvents, then creates incidents.
B.Create a Watchlist in Microsoft Sentinel containing the IP addresses, then write a KQL query in the Hunting blade that joins the Watchlist with DeviceNetworkEvents from Defender for Endpoint.
C.Use the ThreatIntelligenceIndicator table in Microsoft Sentinel, which automatically ingests the feed if you configure a Threat Intelligence - TAXII connector.
D.Manually add each IP address as a custom detection rule in Microsoft Sentinel for each device.
AnswerB

A Watchlist stores the external IP indicators as a reference table, letting a KQL query join them against DeviceNetworkEvents to surface devices contacting those addresses. This satisfies the requirement to hunt proactively across Defender for Endpoint telemetry without waiting for an alert.

Why this answer

The most efficient approach. By creating a Watchlist in Microsoft Sentinel containing the list of known malicious IP addresses, you can write a KQL query in the Hunting blade that joins the Watchlist with the DeviceNetworkEvents table from Defender for Endpoint. This allows you to proactively query for any devices that have communicated with those IPs, even if no alert was generated.

Option A is inefficient because Logic App is designed for automation and orchestration, not for ad-hoc hunting queries. Option C would require configuring a Threat Intelligence - TAXII connector with the specific feed, and the ThreatIntelligenceIndicator table may not contain the custom IP list. Option D is impractical for a large number of IPs and devices.

112
MCQmedium

Your organization uses Microsoft Sentinel with custom analytics rules. During a threat hunt, you want to identify lateral movement using pass-the-hash techniques. Which data source combination is most effective?

A.Azure AD sign-in logs and Office 365 audit logs
B.DeviceEvents and DeviceLogonEvents from Microsoft Defender for Endpoint
C.Sysmon Event ID 3 (Network connect) and Windows Firewall logs
D.Windows Security Event ID 4624 (Logon) with LogonType 3 and NTLM attributes
AnswerD

Event 4624 with LogonType 3 and authentication package NTLM indicates a network logon using NTLM, which is exactly what a pass-the-hash attack performs. The logon process NtLmSsp and the authentication package NTLM in the event are key indicators; LogonType 3 signifies remote access to a resource. While normal network shares also create such events, filtering for unusual source workstations or privileged accounts can reveal pass-the-hash activity. This is the most direct Windows Security log source for detecting NTLM-based lateral movement.

Why this answer

Windows Security Event ID 4624 with LogonType 3 (network logon) and NTLM authentication attributes are key indicators of pass-the-hash attacks, as NTLM is the protocol typically exploited. Option A is wrong because Azure AD sign-in logs only cover cloud authentication, not on-premises lateral movement. Option B is wrong because DeviceEvents and DeviceLogonEvents from Microsoft Defender for Endpoint focus on endpoint behavior and do not provide the detailed NTLM attributes needed.

Option C is wrong because Sysmon Event ID 3 and Windows Firewall logs capture network connections, not authentication details.

113
MCQmedium

You are hunting for signs of credential dumping using Mimikatz. Which process events in Microsoft Defender for Endpoint would most likely indicate this activity?

A.A process opening lsass.exe with access to process memory (e.g., PROCESS_VM_READ)
B.A process named powershell.exe making network connections to an external IP
C.A process named svchost.exe spawning from explorer.exe
D.A process named cmd.exe executing whoami
AnswerA

Mimikatz reads credential material directly from LSASS memory, so a process requesting PROCESS_VM_READ against lsass.exe is the strongest signal. Legitimate tools rarely open LSASS with memory-read rights, making this access mask the specific indicator Microsoft Defender for Endpoint surfaces for credential-dumping detection.

Why this answer

Mimikatz typically opens lsass.exe with specific access permissions like PROCESS_VM_READ to read process memory and dump credentials. Options B, C, and D are not specific indicators: PowerShell making network connections is too broad, svchost spawning from explorer is a normal pattern, and cmd executing whoami is not credential dumping.

114
Multi-Selectmedium

Which THREE of the following are valid sources of threat intelligence that can be ingested into Microsoft Sentinel for threat hunting? (Select three.)

Select 3 answers
A.Syslog from a firewall
B.Microsoft Threat Intelligence feed
C.TAXII server
D.Custom threat intelligence via API
E.Azure Policy
AnswersB, C, D

Microsoft Threat Intelligence feed is natively integrated with Microsoft Sentinel, providing curated indicators of compromise from Microsoft's global telemetry. It satisfies the stem's ingestion requirement without custom connectors, unlike external feeds needing API configuration. This built-in source enriches threat hunting queries directly.

Why this answer

Microsoft Sentinel natively ingests threat intelligence through the Microsoft Defender Threat Intelligence (MDTI) connector, so option B (Microsoft Threat Intelligence feed) is a valid source that populates the ThreatIntelligenceIndicator table for hunting. Option C (TAXII server) is correct because Sentinel supports the Threat Intelligence - TAXII data connector, which pulls STIX/TAXII 2.x indicators from a TAXII 2.0/2.1 endpoint. Option D (Custom threat intelligence via API) is correct because Sentinel exposes the Upload Indicators API (Microsoft Sentinel Threat Intelligence Upload API) and the Graph Security tiIndicators API, allowing custom or third-party feeds to be pushed programmatically.

Option A (Syslog from a firewall) is not a threat intelligence source; it is raw log telemetry ingested via the Syslog/CEF connector for detection, not curated indicator data. Option E (Azure Policy) is a governance/compliance service for enforcing resource configurations and has no role in ingesting threat intelligence indicators.

115
MCQmedium

During a threat hunt, you discover a PowerShell script that downloads and executes a payload from a known malicious URL. The script was run on multiple workstations. Which Microsoft Defender XDR action should you take to contain the threat?

A.Run a full antivirus scan on all affected workstations.
B.Add the URL to the custom indicator list in Microsoft Defender XDR.
C.Initiate a device isolation on the affected workstations using Microsoft Defender for Endpoint.
D.Create a custom detection rule in Microsoft Sentinel.
AnswerC

Device isolation severs network connectivity while preserving the endpoint for investigation, immediately halting the malicious PowerShell script's payload execution and preventing lateral movement across the affected workstations. This directly contains the active threat identified during the hunt.

Why this answer

Device isolation in Microsoft Defender for Endpoint immediately contains the threat by disconnecting the affected workstations from the network, preventing further spread or command-and-control communication. Option A only scans but does not prevent re-infection if the payload is still active. Option B blocks the URL but does not remediate already infected machines.

Option D is about detection in Sentinel, not containment.

116
MCQhard

You are analyzing the KQL query above in Microsoft Sentinel. The query is designed to find devices with high outbound SMB (port 445) connections to suspicious public IPs. However, the query returns no results. What is the most likely issue?

A.Port 445 is not used for SMB.
B.The column RemoteIPType does not exist in DeviceNetworkEvents.
C.The materialize function is not allowed in this context.
D.The syntax for the second query is incorrect.
AnswerB

DeviceNetworkEvents lacks a RemoteIPType column, so referencing it makes the query fail silently or return nothing. The schema exposes RemoteIP, RemoteUrl and RemotePort instead; filtering public addresses requires an ipv4_is_private() or similar check on RemoteIP. This schema mismatch, not the SMB filter, explains the empty result set.

Why this answer

The query returns no results most likely because it references a column, RemoteIPType, that does not exist in the DeviceNetworkEvents table in Microsoft Sentinel. Referencing a non-existent column causes a query error or empty result, and RemoteIPType is not a standard schema field in that table.

Exam trap

SC-200 often tests schema familiarity by presenting a plausible-looking but non-existent column, tempting candidates to blame syntax or functions instead of the invalid field reference.

How to eliminate wrong answers

Option A is wrong because port 445 is indeed the standard port for SMB, so the premise of the query is correct. Option C is wrong because the materialize function is allowed in KQL and is commonly used to cache intermediate results; it is not the cause of empty results here. Option D is wrong because the syntax of the second query is not inherently incorrect — the issue is the invalid column reference, not the query structure.

117
MCQeasy

A threat hunter wants to correlate alerts from multiple Microsoft security products in Microsoft Sentinel. Which feature should be used to create a unified incident?

A.Threat Intelligence
B.Jupyter Notebooks
C.Analytics Rules
D.Investigation Graph
AnswerC

Analytics Rules (also called scheduled or incident creation rules) are the correct mechanism in Microsoft Sentinel for correlating alerts from multiple security products into a unified incident. These rules are built on Kusto Query Language (KQL) and can use entity mapping and alert grouping to combine multiple separate alerts—whether from Microsoft Defender, Azure, or third-party connectors—into one incident based on common entities and a defined time window. When a query returns results and incident creation is enabled, Sentinel creates an incident enriched with the matching alerts, which is exactly what a threat hunter needs for correlation.

Why this answer

Analytics Rules in Microsoft Sentinel can be configured to create incidents from alerts across multiple security products, enabling unified incident creation for threat hunting. Option A (Threat Intelligence) is used to import and use threat intelligence feeds, not to create incidents. Option B (Jupyter Notebooks) provides a platform for security analysis and automation using Python, not for incident creation.

Option D (Investigation Graph) is a visual tool for exploring connections between entities in an investigation, not for creating incidents.

118
MCQmedium

During a threat hunt, you notice an anomalous number of failed logon attempts from a single IP address across multiple user accounts in Microsoft Entra ID sign-in logs. What is the most effective next step to determine if this is a brute-force attack?

A.Immediately block the IP address in the firewall
B.Reset passwords for all affected accounts
C.Disable the accounts that had failed logons
D.Correlate with successful logon events from the same IP for those accounts
AnswerD

Correlating successful logon events from the same IP against those accounts reveals whether the failed attempts culminated in compromise, distinguishing brute-force success from mere noise. This directly satisfies the stem's goal of determining whether the activity constitutes an actual brute-force attack rather than isolated failures.

Why this answer

Correlating failed logon attempts with successful logon events from the same IP address for the same accounts is the most effective next step. If a successful logon occurs shortly after failures, it strongly indicates a brute-force attack succeeded. This evidence justifies further action like blocking the IP or resetting the compromised account.

Option A (blocking IP immediately) may be premature without confirming success. Option B (resetting all affected passwords) is disruptive and may not address the root cause if no breach occurred. Option C (disabling accounts) could block legitimate users unnecessarily.

119
Multi-Selecthard

Which THREE of the following are best practices for performing threat hunting in Microsoft Defender XDR? (Select THREE.)

Select 3 answers
A.Focus only on alerts generated by automated detection rules.
B.Limit hunting to a single data source to reduce complexity.
C.Start with a hypothesis based on threat intelligence or recent incidents.
D.Use a combination of KQL queries and built-in hunting capabilities.
E.Leverage advanced hunting across devices, email, and identities.
AnswersC, D, E

A hypothesis grounded in threat intelligence or recent incidents directs hunting toward plausible adversary behaviour rather than unfocused querying. This satisfies the stem's best-practise criterion by making hunting purposeful and evidence-driven within Microsoft Defender XDR.

Why this answer

Option C is correct because effective threat hunting in Microsoft Defender XDR is hypothesis-driven: analysts should begin with a testable hypothesis derived from threat intelligence, known adversary TTPs, or lessons learned from recent incidents, then validate or refute it with data. Option D is correct because advanced hunting in Defender XDR relies on KQL (Kusto Query Language) queries against the unified schema, and combining custom KQL with built-in hunting capabilities (such as built-in queries, hunting graphs, and detection-rule creation from query results) gives both flexibility and efficiency. Option E is correct because Defender XDR's core strength is cross-domain correlation, so hunting should span the unified advanced hunting tables covering devices (DeviceEvents, DeviceProcessEvents), email (EmailEvents, EmailAttachmentInfo), and identities (IdentityLogonEvents, IdentityInfo) to surface multi-stage attacks that a single workload would miss.

Option A is not a best practice because relying only on automated detection alerts is reactive alert triage, not proactive hunting for threats that evade existing detections. Option B is not a best practice because restricting hunting to a single data source defeats the purpose of Defender XDR's unified, cross-domain telemetry and hides correlated attack chains.

Exam trap

SC-200 often tests the misconception that threat hunting equals reviewing automated alerts, when the exam expects candidates to recognize hunting as a proactive, hypothesis-driven, cross-domain activity.

120
MCQhard

An organization uses Microsoft Defender for Endpoint (MDE) to hunt for signs of credential dumping. An analyst runs a custom advanced hunting query that searches for processes accessing LSASS.exe. The query uses DeviceProcessEvents and DeviceFileEvents. The analyst notices that some known credential dumping tools are detected, but they want to find previously unknown variants. Which approach should the analyst take to improve the hunt?

A.Enable LSASS auditing via Windows Security Event Log.
B.Focus on file reputation data to exclude clean files.
C.Add more signature-based indicators to the query.
D.Look for anomalous LSASS access patterns using process lineage and call stacks.
AnswerD

Signature-based matching only catches known tools, so behavioural analysis is needed. Correlating process lineage and call stacks exposes anomalous LSASS access by novel variants, satisfying the requirement to detect previously unknown credential dumping tools rather than relying on known indicators.

Why this answer

To catch previously unknown credential-dumping variants, the analyst must move beyond signature and file-reputation indicators and instead hunt for behavioral anomalies in how processes access LSASS. Analyzing process lineage (which parent spawned the accessing process) and call stacks (which modules and functions are invoking LSASS) surfaces suspicious patterns like unsigned binaries, unusual parent-child relationships, or direct syscalls that signature-based detections miss. This is the essence of hypothesis-driven, behavior-based hunting in MDE advanced hunting.

Exam trap

SC-200 often tests the distinction between signature-based detection (which only catches known threats) and behavior-based hunting (which finds unknown variants) — candidates who default to 'add more indicators' fall for the signature trap.

How to eliminate wrong answers

Option A is wrong because enabling LSASS auditing via the Windows Security Event Log produces Event ID 4656/4663 entries but does not itself improve the KQL hunt in MDE and is noisy and limited in scope. Option B is wrong because file reputation data only helps exclude known-good files; it does nothing to reveal unknown malicious variants and can cause false negatives if a malicious file has a signed or reputable-looking hash. Option C is wrong because adding more signature-based indicators is a detection-engineering approach that only catches known tools and directly contradicts the goal of finding unknown variants.

121
MCQeasy

You are a threat hunter and you want to identify potential lateral movement in your environment. Which Microsoft Defender XDR hunting table would you query to find network connections from a compromised workstation to other internal devices?

A.DeviceProcessEvents
B.DeviceLogonEvents
C.DeviceNetworkEvents
D.DeviceFileEvents
AnswerC

DeviceNetworkEvents records inbound and outbound network connections with remote IP addresses, ports and initiating processes, so querying it reveals a compromised workstation connecting to other internal devices — exactly the lateral movement indicator the hunt requires.

Why this answer

DeviceNetworkEvents is the correct table because it records network connection telemetry from Defender for Endpoint sensors, including outbound and inbound connections, remote IPs, ports, and the initiating process. Lateral movement typically manifests as SMB, RDP, WinRM, or other internal connections from a compromised host to peer systems, all of which appear in this table. Querying DeviceNetworkEvents lets you correlate the initiating process with remote endpoints to spot anomalous east-west traffic.

The other tables capture process, logon, or file activity, not raw network connection details.

Exam trap

SC-200 often tests whether candidates can distinguish between endpoint telemetry tables by their core data type, and the trap is confusing process execution (DeviceProcessEvents) with network connection activity (DeviceNetworkEvents) when hunting for lateral movement.

How to eliminate wrong answers

Option A is wrong because DeviceProcessEvents records process creation, command-line arguments, and parent-child process relationships, but it does not contain remote IP addresses or network connection metadata needed to identify lateral movement targets. Option B is wrong because DeviceLogonEvents captures authentication events (successful and failed logons, logon types, and account details) but lacks the network connection context such as remote IPs and ports that indicate lateral movement paths. Option D is wrong because DeviceFileEvents tracks file creation, modification, and deletion activity, which is unrelated to identifying network connections between internal devices.

122
MCQeasy

During a threat hunt in Microsoft Defender XDR, you notice repeated failed logon attempts from an IP address that belongs to a known anonymizer service. What is the first action you should take?

A.Block the IP address in Microsoft Defender for Cloud Apps.
B.Create an analytics rule in Microsoft Sentinel to alert on all anonymizer IP addresses.
C.Initiate an investigation by reviewing the impacted user accounts and endpoints for signs of compromise.
D.Report the IP to the Microsoft Sentinel Threat Intelligence team.
AnswerC

The correct initial action in a threat hunt is to pivot from the observed indicator—the anonymizer IP—to the associated entities, specifically the impacted user accounts and endpoints, and examine authentication logs, behavioral anomalies, and device telemetry for evidence of unauthorized access or lateral movement. Microsoft Defender XDR provides integrated signals such as IdentityLogonEvents, DeviceNetworkEvents, and alerts that enable this scoping, aligning with the MITRE ATT&CK technique of discovering the full attack surface. Only after determining whether accounts are compromised and what systems are affected can you make informed decisions on containment and remediation.

Why this answer

In a threat hunt, the discovery of failed logons from an anonymizer IP is a potential indicator of compromise (IoC) that requires immediate validation. The first action should be to investigate the impacted user accounts and endpoints to determine if any logons succeeded or if there are other signs of malicious activity. This aligns with the incident response process of identification and scoping before taking containment or remediation actions.

Blocking or creating rules without understanding the scope could disrupt legitimate activity or miss broader compromise.

Exam trap

SC-200 often tests the order of incident response steps, and candidates may confuse containment with investigation, picking a blocking action before verifying the threat.

How to eliminate wrong answers

Option A is wrong because blocking the IP in Defender for Cloud Apps is a containment action that should follow investigation, not precede it; it may also be ineffective if the attacker uses multiple IPs. Option B is wrong because creating an analytics rule is a proactive detection measure, not an immediate response to a specific potential incident; it doesn't address the current threat. Option D is wrong because reporting the IP to Microsoft's threat intelligence team is not a standard first response action and does not help mitigate the immediate risk to the organization.

123
MCQmedium

During a threat hunting exercise, an analyst discovers a suspicious PowerShell process that executed encoded commands and made outbound connections to an unknown IP address. The process tree shows it was spawned by a Microsoft Word instance. What is the most likely attack technique being observed?

A.Service Execution
B.Phishing with malicious macro
C.Execution via Rundll32
D.Lateral Movement via WMI
AnswerB

Phishing with malicious macro is correct because the suspicious chain—Microsoft Word spawning PowerShell with an encoded command line—is a classic indicator of a macro-enabled Office document used as an initial access vector. Attackers embed VBA macros that invoke PowerShell via a WMI CreateProcess or direct CreateProcess call, often using -EncodedCommand or -EncodedArguments to hide the payload from command-line logging and initial inspection. This aligns with MITRE ATT&CK techniques T1566.001 (Spearphishing Attachment) and T1204.002 (User Execution: Malicious File), where the macro acts as the execution trigger and PowerShell serves as the download cradle or in-memory loader.

Why this answer

A Microsoft Word process spawning PowerShell that then runs encoded commands and beacons to an unknown external IP is the textbook signature of a malicious macro. Office macros (VBA) are commonly used to launch PowerShell with -EncodedCommand, which base64-encodes the payload to evade string-based detection. The parent-child relationship (WINWORD.EXE → powershell.exe) combined with outbound C2 traffic confirms macro-based initial execution and command-and-control.

Exam trap

SC-200 often tests whether candidates can distinguish initial-access techniques (phishing/macro) from later-stage techniques (lateral movement, service execution) by reading the process tree carefully — the Word parent is the giveaway that this is initial execution, not post-exploitation.

How to eliminate wrong answers

Option A is wrong because 'Service Execution' is not a recognized MITRE ATT&CK technique; the closest real technique is T1569 System Services, which involves PsExec or service creation, not Office spawning PowerShell. Option C is wrong because Rundll32 execution would show rundll32.exe as the child process loading a DLL or JavaScript/VBScript, not powershell.exe with encoded commands. Option D is wrong because WMI lateral movement would appear as wmic.exe or Win32_Process Create events on a remote host, and there is no evidence of remote execution or a second machine in the process tree.

124
MCQmedium

You are performing a threat hunt in Microsoft Sentinel and have a KQL query that returns a high number of false positives. You want to reduce the noise without missing real threats. Which approach should you take?

A.Write a KQL query that looks for uncommon process chains, such as wscript.exe launched from Microsoft Office.
B.Add a filter to exclude all Microsoft signed processes.
C.Remove the time filter and run the query against all historical data.
D.Broaden the time range to capture more data.
AnswerA

A KQL query targeting uncommon process chains, such as wscript.exe spawned from Microsoft Office, directly identifies suspicious child-process relationships that align with known script-based attack sequences (macro execution, DDE abuse). By focusing on the parent-child correlation rather than broad attributes, the query maintains a low false-positive rate because it only surfaces events matching a specific, behaviorally suspicious pattern, not every process creation.

Why this answer

Option A is correct because focusing on uncommon process chains—like wscript.exe spawned by Microsoft Office—targets specific, high-fidelity indicators of malicious activity (e.g., macro-based attacks) rather than relying on broad, noisy signatures. This approach reduces false positives by filtering out normal, benign process relationships while preserving detection of real threats that deviate from baseline behavior. In Microsoft Sentinel, such behavioral hunting queries leverage KQL joins and process lineage to surface anomalies that are more likely to be true positives.

Exam trap

SC-200 often tests the misconception that reducing false positives means filtering out broad categories like signed processes or expanding data scope, when in fact it requires precise, behavior-based indicators that balance noise reduction with threat coverage.

How to eliminate wrong answers

Option B is wrong because excluding all Microsoft signed processes would create a massive blind spot: attackers often use signed binaries (LOLBins) like PowerShell or wscript.exe for malicious purposes, so this filter would suppress many real threats. Option C is wrong because removing the time filter and querying all historical data would drastically increase the volume of results, amplifying false positives and making triage impractical; it does not reduce noise. Option D is wrong because broadening the time range captures more data, which typically increases the number of false positives and does not address the root cause of noise; it may also dilute the signal-to-noise ratio.

125
MCQmedium

Your threat hunting hypothesis is that a user's credentials were used to sign in from two geographically distant locations within a short time. In Microsoft Defender for Cloud Apps, which log type would you query in Microsoft Sentinel to detect impossible travel?

A.SigninLogs
B.AuditLogs
C.CommonSecurityLog
D.OfficeActivity
AnswerA

SigninLogs in Microsoft Sentinel records Microsoft Entra ID sign-in events with IP-derived location and timestamp data. Querying it lets you correlate two authentications from geographically distant locations within an implausible interval, directly testing the impossible travel hypothesis.

Why this answer

Impossible travel detection relies on analyzing sign-in events with their source IP geolocation and timestamps. In Microsoft Sentinel, Azure AD (Entra ID) sign-in events are stored in the SigninLogs table, which contains fields like IPAddress, Location, and TimeGenerated needed to compute whether a user signed in from two distant locations within an implausible timeframe. Defender for Cloud Apps surfaces these as impossible travel alerts, but the underlying Sentinel query targets SigninLogs.

Exam trap

The trap is confusing sign-in telemetry with activity telemetry — candidates may pick OfficeActivity because the user 'did something,' but impossible travel specifically requires sign-in geolocation data, which lives in SigninLogs.

How to eliminate wrong answers

Option B is wrong because AuditLogs contains directory and administrative activity (user creation, role changes, policy updates), not interactive sign-in events with geolocation. Option C is wrong because CommonSecurityLog holds CEF-formatted data from third-party security appliances (firewalls, proxies, IDS), not Azure AD sign-in telemetry. Option D is wrong because OfficeActivity captures user actions within Office 365 workloads (file access, email, SharePoint), which may show activity but lacks the sign-in geolocation context needed for impossible travel.

126
MCQhard

An analyst uses this KQL query in Microsoft Sentinel to hunt for potential brute-force attacks. What is the primary purpose of the join operation?

A.To filter out IP addresses that have only successful logons
B.To identify accounts that had both a high number of failed logons and at least one successful logon from the same IP
C.To calculate the ratio of failed to successful logons for each account
D.To remove duplicate entries of account and IP combinations
AnswerB

This is correct. The query first aggregates failed logon events by account and IP, then performs an inner join with successful logon events on the same account/IP pair. The inner join ensures that any matched row has at least one successful logon from that IP, while the aggregate count shows a high number of failures. Together these filters reveal accounts that suffered many failed logon attempts and ultimately had a successful logon from the same source IP—a classic indicator of a successful brute-force attack.

Why this answer

The join in the KQL query correlates failed logon events with successful logon events on the same account and IP, so its primary purpose is to surface accounts that experienced many failed logons followed by at least one success from the same IP — a classic brute-force success indicator. This narrows the hunt to high-risk accounts rather than all failed logons.

Exam trap

SC-200 often tests KQL join semantics and detection logic, and the trap is misreading the join as a simple filter or deduplication when it is actually correlating two event sets to identify accounts with both failed and successful logons from the same IP.

How to eliminate wrong answers

Option A is wrong because the join is not merely filtering out IPs with only successful logons — it is correlating failed and successful events to find accounts with both, which is a more specific detection. Option C is wrong because the query does not compute a ratio of failed to successful logons; it identifies the co-occurrence of high failures and at least one success. Option D is wrong because the join is not a deduplication operation — deduplication would use distinct or summarize, not a join between two event sets.

127
MCQeasy

Your threat hunting team uses Microsoft Sentinel. They want to search for anomalous network connections to known malicious IP addresses over the past 7 days. Which KQL operator should they use to match the source IP addresses against a watchlist containing the malicious IPs?

A.where
B.in
C.has
D.contains
AnswerB

The in operator tests whether a value exists in a dynamic list or watchlist, so source IPs can be matched directly against the malicious IP set. It satisfies the requirement to compare network connection sources with watchlist entries over the past seven days.

Why this answer

The 'in' operator is the correct choice because it checks whether a value (the source IP) exists within a specified set — here, the dynamic list of malicious IPs pulled from a Sentinel watchlist via _GetWatchlist(). This is the idiomatic KQL pattern for matching against watchlists and produces an efficient membership test rather than a substring search.

Exam trap

SC-200 often tests the confusion between substring operators ('contains'/'has') and set-membership ('in'), tricking candidates into picking 'contains' for exact indicator matching against watchlists.

How to eliminate wrong answers

Option A is wrong because 'where' is a tabular filter operator that selects rows based on a predicate; it is not itself a membership operator and must be combined with something like 'in' to compare against a watchlist. Option C is wrong because 'has' performs a term-based (indexed) match suited to full-text token searches, not exact IP membership, and can produce false matches on tokenized strings. Option D is wrong because 'contains' does a case-insensitive substring match, which is slower and can incorrectly match partial IP strings (e.g., '10.0.0.1' inside '10.0.0.10').

128
MCQmedium

A security analyst is performing threat hunting in Microsoft Sentinel and wants to identify anomalous outbound network connections from a compromised workstation. The analyst suspects that a beaconing pattern is present. Which KQL function is most appropriate to detect periodic beaconing behavior over time?

A.series_decompose(TimeGenerated)
B.make_list(TimeGenerated)
C.startofday(TimeGenerated)
D.bin(TimeGenerated, 1h)
AnswerC

startofday(TimeGenerated) truncates each timestamp to the beginning of its calendar day, so grouping by this expression counts events per day. For a host that beacons once daily, the daily event count will remain consistently near one per day, making the periodic pattern easy to spot with a simple summarize query. This directly aligns with the hypothesis of a daily beacon and is the most appropriate choice among the options for detecting periodicity in typical C2 traffic.

Why this answer

`startofday` groups timestamps by day, enabling analysts to count events per day and identify regular intervals characteristic of beaconing (e.g., daily connections). Option A is incorrect: `series_decompose` is used for time series decomposition (trend, seasonal, residual) but is not the most direct method for detecting periodic beaconing; it is more complex and typically used after aggregation. Option B is incorrect: `make_list` creates a list of values, not useful for periodicity detection.

Option D is incorrect: `bin(TimeGenerated, 1h)` bins events into hourly buckets, which could detect beaconing at finer granularity, but daily beaconing is better suited to `startofday`; `bin` is not specifically for periodic pattern detection.

129
Multi-Selectmedium

Which TWO of the following are valid methods to detect Kerberoasting attacks during a threat hunt? (Select TWO.)

Select 2 answers
A.Service account logon events with RC4 encryption type.
B.Multiple Kerberos TGS requests from a single user account to multiple service accounts.
C.Unusual number of LDAP queries from a domain controller.
D.High volume of NTLM authentication failures from a single IP.
E.Detection of forged Kerberos tickets (Golden Ticket) in the domain.
AnswersA, B

Kerberoasting requests RC4-encrypted service tickets, so hunting for service account logon events showing RC4 (0x17) encryption type exposes the attack, since legitimate modern service authentication typically negotiates AES. This satisfies the stem's detection requirement by targeting the encryption downgrade inherent to extracting crackable ticket hashes.

Why this answer

Option A is correct because Kerberoasting requests TGS tickets for service accounts and the attacker typically requests RC4 (etype 0x17) encryption to make offline cracking of the service account hash easier, so service account logon events showing RC4 encryption (Event ID 4769 with Ticket Encryption Type 0x17) are a strong hunting indicator. Option B is correct because a single user account rapidly requesting multiple TGS tickets for many different service accounts (SPNs) is a hallmark of automated Kerberoasting enumeration and ticket harvesting. Option C is not specific to Kerberoasting, since LDAP query volume anomalies can reflect many other reconnaissance or administrative activities.

Option D concerns NTLM authentication failures, which are unrelated to Kerberos TGS abuse. Option E describes Golden Ticket detection, which involves forged TGTs and KRBTGT compromise, not Kerberoasting's TGS request behavior.

130
MCQmedium

During a threat hunt in Microsoft Sentinel, you want to find hosts that began communicating with a newly registered domain shortly after a suspicious process executed on the same host. Your data is in DeviceProcessEvents and DeviceNetworkEvents. Which approach best correlates process execution and subsequent network connections on the same device within a time window?

A.Join DeviceProcessEvents and DeviceNetworkEvents on DeviceId with a time-window condition that places the network event after the process event
B.Union DeviceProcessEvents and DeviceNetworkEvents and filter by timestamp
C.Summarize each table by DeviceId and compare the resulting counts
D.Join the two tables on the process name and remote IP address
AnswerA

Joining on DeviceId and constraining the network timestamp to fall shortly after the process timestamp links the suspicious execution to the outbound connection on the same host. This preserves the causal sequence the hunt hypothesis depends on and avoids correlating unrelated activity.

Why this answer

Correlating execution to later network activity requires a device-scoped join with a temporal constraint. Joining on DeviceId and requiring the network timestamp to be later than the process timestamp, within a bounded window, preserves causality and keeps unrelated hosts out of the result, which is what the hunt hypothesis needs.

Exam trap

The trap here is joining on process name or remote IP, which are not unique identifiers, instead of using DeviceId with an explicit time-window condition.

131
MCQmedium

While hunting, you notice a user account has been created and then immediately added to the Domain Admins group. Which table in Microsoft 365 Defender should you query to find this event?

A.IdentityQueryEvents
B.IdentityLogonEvents
C.DeviceEvents
D.IdentityDirectoryEvents
AnswerD

IdentityDirectoryEvents is the correct table because it contains audit records of directory service state changes, including user account creation, deletion, password resets, and group membership updates. When a user account appears in Active Directory or Azure AD, the corresponding ActionType and target object details are logged here. This makes it the definitive source for hunting accounts that have been newly added or modified by an attacker.

Why this answer

IdentityDirectoryEvents is the correct table because it records directory-service and identity-management events in Microsoft Defender XDR, including account creation, group membership changes, and role assignments such as adding a user to Domain Admins. This table captures the 'who did what to which identity object' details needed to hunt for privilege escalation via group membership. IdentityLogonEvents covers authentication activity, not directory object changes, so it would not show the group addition.

Exam trap

SC-200 often tests the confusion between IdentityLogonEvents (authentication) and IdentityDirectoryEvents (directory object changes) — candidates must remember that group membership changes are directory events, not logon events.

How to eliminate wrong answers

Option A is wrong because IdentityQueryEvents records directory query operations (e.g., LDAP queries performed by tools like BloodHound or AdFind), not the actual account creation or group membership modification. Option B is wrong because IdentityLogonEvents captures logon and authentication events (successful/failed sign-ins), not directory object changes like adding a user to a privileged group. Option C is wrong because DeviceEvents covers endpoint-level events such as process creation, file writes, and registry changes on devices, not Active Directory group membership changes.

132
MCQmedium

During a threat hunt, you find an alert for a suspicious PowerShell script that encoded a payload. You want to decode the script to understand its intent. Which Microsoft Sentinel feature can assist with this task?

A.Playbooks
B.Workbooks
C.Hunting blade with KQL using base64_decode_tostring()
D.Analytics rules
AnswerC

The Hunting blade in Microsoft Sentinel provides a KQL query environment tailored for proactive threat hunting. KQL includes built-in string functions, and base64_decode_tostring() specifically converts a Base64-encoded input to its plain-text string representation, which is ideal for decoding obfuscated PowerShell commands that attackers often encode using Base64. Running a KQL query against the relevant table (e.g., DeviceProcessEvents) with this function reveals the actual command executed, enabling further analysis. This is the correct approach because it directly transforms the encoded data into readable content.

Why this answer

Microsoft Sentinel's Hunting blade allows security analysts to run KQL queries across logged data. The function base64_decode_tostring() can decode Base64-encoded strings, such as those found in obfuscated PowerShell scripts. This enables threat hunters to reveal the script's intent.

Playbooks are for automation, Workbooks for visualization, and Analytics rules for alert generation, none of which directly decode payloads.

Exam trap

The trap is confusing Sentinel features: candidates might think Playbooks or Analytics rules can decode data, but only the Hunting blade with KQL provides that capability.

How to eliminate wrong answers

Option A is wrong because Playbooks are automated workflows triggered by incidents, not for ad-hoc decoding. Option B is wrong because Workbooks are dashboards for visualizing data, not for decoding. Option D is wrong because Analytics rules are used to create alerts based on queries, not for interactive decoding.

133
Multi-Selectmedium

Which THREE of the following are key components of a successful threat hunting program in a Microsoft Defender XDR environment?

Select 3 answers
A.Deep understanding of normal network behavior
B.A clear hypothesis based on threat intelligence
C.Use of MITRE ATT&CK framework
D.Automated incident response playbooks
E.Reactive response to alerts
AnswersA, B, C

Baselining normal network behaviour lets hunters spot anomalies such as beaconing, unusual lateral movement or data staging in Defender XDR telemetry. Without knowing what routine traffic looks like, distinguishing genuine malicious activity from benign administrative patterns is impossible, so this underpins every hypothesis.

Why this answer

A successful threat hunting program in Microsoft Defender XDR requires a deep understanding of normal network behavior (A), because establishing a baseline of legitimate activity lets hunters spot anomalies across endpoint, identity, email, and cloud telemetry that automated detections may miss. A clear hypothesis based on threat intelligence (B) is essential, since threat hunting is hypothesis-driven rather than alert-driven; hunters use intel to form testable assumptions about adversary behavior and then query Defender XDR advanced hunting (KQL) to validate or refute them. The use of the MITRE ATT&CK framework (C) is also a key component, as it maps observed techniques and tactics to a common taxonomy, helping hunters prioritize coverage gaps and structure hunts around known adversary TTPs.

Automated incident response playbooks (D) belong to SOAR/automated investigation and response, not threat hunting, and reactive response to alerts (E) is the opposite of proactive hunting, so neither is a core component of a threat hunting program.

Exam trap

SC-200 often tests the distinction between proactive threat hunting (hypothesis, MITRE ATT&CK, baselining) and reactive incident response (playbooks, alert triage), tempting candidates to select automation options.

134
Multi-Selecteasy

Which TWO data sources are commonly used in Microsoft Sentinel for threat hunting related to lateral movement? (Select TWO.)

Select 2 answers
A.SigninLogs
B.SecurityEvent
C.OfficeActivity
D.DeviceNetworkEvents
E.AuditLogs
AnswersB, D

SecurityEvent is a primary data source for lateral movement because it ingests Windows security audit events from event log channels such as Security and Sysmon. Events like 4624 (successful logon, especially type 3 network logons), 4688 (process creation), and 4648 (explicit logon credentials) let analysts spot pass-the-hash, remote logon, and service creation by attackers. These host-level audit trails provide the ground truth needed to reconstruct a kill chain as an adversary moves between machines.

Why this answer

SecurityEvent (B) is correct because it captures Windows Security event log data forwarded via AMA/Log Analytics, including logon events (4624, 4625), explicit credential use (4648), and special privilege assignment (4672) that are the primary telemetry for detecting lateral movement techniques like pass-the-hash and RDP pivoting. DeviceNetworkEvents (D) is correct because it comes from Microsoft Defender for Endpoint and records inbound/outbound network connections with process, IP, and port context, which is essential for spotting lateral movement such as SMB (445), WMI, PsExec, and remote service creation across hosts. SigninLogs (A) is not among the marked answers: it covers Entra ID authentication events and is more relevant to identity-based attacks and initial access than host-to-host lateral movement.

OfficeActivity (C) tracks SharePoint, Exchange, and Teams user actions, which relate to data exfiltration or phishing rather than lateral movement across endpoints. AuditLogs (E) records Entra ID directory changes such as role assignments and app registrations, which support privilege escalation and persistence investigations, not lateral movement hunting.

Exam trap

The trap is picking identity-centric tables like SigninLogs or AuditLogs because lateral movement sounds like an authentication issue — but the exam expects you to recognize that host-level (SecurityEvent) and network-level (DeviceNetworkEvents) telemetry is what actually reveals movement between machines.

135
Multi-Selecthard

Which TWO actions are part of the threat hunting process in Microsoft Sentinel?

Select 2 answers
A.Creating custom hunting queries based on hypotheses.
B.Using bookmarks to preserve interesting findings.
C.Setting up data connectors to ingest logs.
D.Fine-tuning the severity of analytical rules.
E.Configuring scheduled analytics rules.
AnswersA, B

Custom hunting queries operationalise a hypothesis by searching ingested log data for indicators that automated analytics have not flagged, satisfying the proactive, hypothesis-driven requirement of threat hunting in Microsoft Sentinel. Unlike scheduled analytics rules, which trigger alerts reactively, hunting queries are run on demand and their results can be promoted into detections.

Why this answer

Option A is correct because threat hunting in Microsoft Sentinel is hypothesis-driven: analysts write custom hunting queries (KQL) in the Hunting blade to proactively search ingested data for signs of compromise that existing detections may have missed. Option B is correct because bookmarks let hunters capture and preserve interesting query results, entities, and findings so they can be retained, shared, and later promoted into incidents or used to build new analytics rules. The other options are not part of the hunting process itself: C (data connectors) is a data ingestion/onboarding task, D (severity tuning) is detection tuning, and E (scheduled analytics rules) is detection engineering, all of which support but are distinct from proactive threat hunting.

136
Multi-Selecthard

Which THREE actions should a threat hunter take when using Microsoft Defender XDR advanced hunting to investigate a potential ransomware outbreak? (Select THREE.)

Select 3 answers
A.Check for service installation events that mimic system services.
B.Review mailbox audit logs for email forwarding rules.
C.Inspect scheduled tasks for persistence mechanisms.
D.Correlate process creation events with file modification events.
E.Review password change events for service accounts.
AnswersA, C, D

Ransomware actors frequently register malicious binaries as Windows services to survive reboots and gain SYSTEM-level execution. Querying service installation events in advanced hunting exposes this persistence technique, satisfying the hunt's requirement to uncover stealthy ransomware footholds beyond initial encryption activity.

Why this answer

Option A is correct because ransomware operators frequently install malicious services with names that mimic legitimate system services (for example, svchost-like or Windows Update-like names) to achieve persistence and evade detection, so hunting service installation events in DeviceEvents (ActionType == 'ServiceInstalled') surfaces this masquerading behavior. Option C is correct because scheduled tasks are a common ransomware persistence mechanism; hunting TaskScheduler events such as TaskCreated/TaskUpdated in DeviceEvents reveals malicious tasks that re-launch the encryptor or payload after reboot. Option D is correct because correlating ProcessCreate events with FileModified/FileCreated events (for example, a process spawning and then rapidly modifying or renaming many files with extensions like .locked) exposes the encryption behavior that is the hallmark of a ransomware outbreak.

Option B does not belong because mailbox audit logs and email forwarding rules are relevant to business email compromise or phishing investigations, not to endpoint ransomware encryption activity in advanced hunting. Option E does not belong because password change events for service accounts relate to credential abuse or account takeover detection, which is not the primary evidence of an active ransomware outbreak on endpoints.

Exam trap

SC-200 often tests the specific artifacts relevant to ransomware versus other attack types; candidates may select email-related actions due to the initial access vector, but the question asks about investigating the outbreak itself.

137
MCQeasy

A threat hunter wants to proactively search for signs of ransomware activity in the environment using Microsoft Sentinel. Which data source is most likely to provide early indicators of ransomware, such as mass file renaming or encryption?

A.Azure AD sign-in logs
B.Microsoft Defender for Endpoint advanced hunting tables like DeviceFileEvents and DeviceProcessEvents
C.Azure Activity Log
D.Office 365 audit logs (UnifiedAuditLog)
AnswerB

DeviceFileEvents records file creation, renaming and modification, exposing the mass rename and encryption patterns ransomware produces. DeviceProcessEvents supplies the spawning processes behind that activity, giving hunters early endpoint-level indicators rather than relying on network or email telemetry.

Why this answer

(Microsoft Defender for Endpoint) provides advanced hunting on endpoint processes and file events, which can detect mass file modifications indicative of ransomware. Option A (Azure AD sign-in logs) logs authentication events. Option C (Azure Activity Log) logs control plane operations.

Option D (Office 365 audit logs) logs cloud app activities.

138
Multi-Selectmedium

Which TWO actions are valid when performing threat hunting in Microsoft Sentinel using hunting queries? (Choose two.)

Select 2 answers
A.Bookmark specific rows of results for later investigation.
B.Create a custom detection rule based on a hunting query.
C.Schedule a hunting query to run every hour.
D.Automatically trigger an alert when a hunting query returns results.
E.Export results directly to Azure Blob Storage.
AnswersA, B

Bookmarking preserves specific result rows, together with their entities and timestamps, so they can be revisited, tagged and investigated later. This satisfies the valid hunting action of retaining evidence from query output rather than losing it when the results grid is refreshed.

Why this answer

Option A is correct because Microsoft Sentinel hunting queries return results in Logs, and an analyst can select rows and create bookmarks to preserve those findings and pivot them into an investigation. Option B is correct because a hunting query can be converted into a custom analytics rule, which then runs on a schedule and generates incidents/alerts for ongoing detection. Option C is not valid because hunting queries are ad hoc/manual by design; scheduling and alerting are functions of analytics rules, not the hunting query itself.

Option D is likewise not valid for hunting queries, since automatic alerting on query results requires an analytics rule. Option E is not a built-in hunting-query action; exporting to Azure Blob Storage would require separate tooling or workflows, not a native hunting query operation.

Exam trap

SC-200 often tests the confusion between hunting queries and analytics rules, so candidates must remember that hunting queries are manual and cannot be scheduled or alert automatically.

139
Multi-Selecthard

Which THREE techniques would you use in Microsoft Sentinel to hunt for data exfiltration over DNS?

Select 3 answers
A.Analyze DNS query logs for high volume or long subdomains
B.Examine network traffic logs for large data transfers to known cloud storage IPs
C.Correlate DNS events with process creation events to identify the process making queries
D.Review email forwarding rules for external domains
E.Use ASIM DNS parsers to normalize DNS logs and detect anomalies
AnswersA, C, E

DNS tunneling commonly encodes data in the subdomain portion of a query name, so attackers craft unusually long subdomains (often 50+ characters) and generate a high query volume to a single authoritative domain. By analyzing DNS query logs for these patterns—such as label length, entropy, and query frequency per domain—you can directly detect the covert channel. This technique is effective because DNS traffic is frequently allowed through firewalls without deep inspection, making the logs the primary evidence of the exfiltration.

Why this answer

Option A is correct because DNS tunneling and exfiltration typically manifest as unusually high query volumes to a single domain or abnormally long subdomain labels that encode stolen data, so analyzing DNS query logs for these patterns is a core hunting technique in Microsoft Sentinel. Option C is correct because correlating DNS events with process creation events (for example via SecurityEvent 4688 or Sysmon Event ID 1) lets you identify which executable or script is generating the suspicious queries, distinguishing malicious tooling from legitimate resolvers. Option E is correct because ASIM (Advanced Security Information Model) DNS parsers normalize DNS logs from multiple sources into a common schema, enabling consistent anomaly detection and cross-source correlation across the workspace.

Option B is not part of DNS exfiltration hunting since it focuses on large transfers to cloud storage IPs, which is HTTP/HTTPS exfiltration rather than DNS-based. Option D is also unrelated, as email forwarding rules address exfiltration via email (for example Exchange transport rules) and not DNS tunneling.

Exam trap

SC-200 often tests whether candidates confuse DNS exfiltration with other exfiltration channels (HTTP, email), so options describing large transfers or email rules are distractors for a DNS-specific hunt.

140
Multi-Selecthard

Which THREE Microsoft Sentinel features are specifically designed to assist with threat hunting?

Select 3 answers
A.Livestream for real-time hunting.
B.Workbooks for interactive dashboards.
C.Bookmarks to record interesting results.
D.Automation rules to respond to incidents.
E.The Hunting blade with built-in and custom queries.
AnswersA, C, E

Livestream streams events in real time as they are ingested, letting hunters watch activity unfold without waiting for scheduled analytics rules to fire. This satisfies the scenario's requirement for a hunting feature, since interactive, near-instant event visibility directly supports proactive investigation rather than automated detection alone.

Why this answer

Option A, Livestream for real-time hunting, is correct because Microsoft Sentinel's Livestream feature lets analysts run a hunting query continuously and view results as they occur, which is specifically built for interactive, real-time threat hunting rather than post-incident reporting. Option C, Bookmarks to record interesting results, is correct because bookmarks preserve notable entities, events, or query results from hunting activities so they can be retained, tagged, and later promoted into incidents or used in investigations. Option E, The Hunting blade with built-in and custom queries, is correct because the Hunting blade in Microsoft Sentinel provides prebuilt KQL hunting queries mapped to MITRE ATT&CK techniques plus the ability to create and run custom queries, making it the core hunting workspace.

Option B, Workbooks for interactive dashboards, is not marked correct because workbooks are primarily used for visualization, monitoring, and reporting on data rather than being a dedicated hunting tool. Option D, Automation rules to respond to incidents, is not marked correct because automation rules orchestrate incident handling, triage, and response actions, which is an SOAR capability rather than a threat-hunting feature.

141
Multi-Selectmedium

Which TWO are valid methods for performing threat hunting in Microsoft Sentinel? (Choose two.)

Select 2 answers
A.Using playbooks to respond to incidents
B.Using the Hunting blade with built-in queries
C.Using the MITRE ATT&CK dashboard
D.Using Jupyter notebooks with MSTICpy
E.Using watchlists to create alerts
AnswersB, D

The Hunting blade provides built-in, pre-built queries that run directly against your Log Analytics workspace, letting analysts pivot on entities and surface suspicious activity without authoring KQL from scratch. This satisfies the stem's requirement for a valid threat-hunting method in Microsoft Sentinel, complementing custom query development.

Why this answer

Option B is correct because the Hunting blade in Microsoft Sentinel provides built-in, pre-designed hunting queries (based on KQL) that analysts can run across Log Analytics workspaces to proactively search for suspicious activity, which is a core threat-hunting method. Option D is correct because Microsoft Sentinel supports Jupyter notebooks integrated with MSTICpy, a Python library that enables advanced, customizable threat-hunting workflows such as querying logs, enriching data with threat intelligence, and visualizing results. Option A is not a hunting method but an automated incident-response capability (playbooks built on Logic Apps).

Option C is incorrect because the MITRE ATT&CK dashboard/page in Sentinel is used for coverage mapping and understanding detections, not as a primary threat-hunting technique. Option E is incorrect because watchlists are used to store reference data (e.g., IPs, users) for correlation and can drive analytics rules, but creating alerts from watchlists is detection engineering, not threat hunting.

Exam trap

SC-200 often tests the distinction between hunting (proactive, query-driven) and detection/response (playbooks, watchlists, analytics rules), causing candidates to select response-oriented features as hunting methods.

142
MCQmedium

During a threat hunt, you discover suspicious PowerShell commands executed on multiple workstations. Which KQL function in Microsoft Sentinel is most effective for aggregating similar commands to identify a pattern?

A.summarize
B.extend
C.search
D.project
AnswerA

summarize groups rows by chosen keys and computes aggregates such as count or make_set, letting you collapse many similar PowerShell command lines into per-host or per-command patterns. That aggregation exposes commands recurring across workstations, which raw row-by-row output obscures.

Why this answer

The summarize operator in KQL groups rows by specified columns and computes aggregations such as count, making it ideal for aggregating similar PowerShell commands to reveal patterns. By summarizing on CommandLine or a normalized field, analysts can count occurrences and spot outliers. The other operators transform or filter but do not aggregate.

Exam trap

SC-200 often tests KQL operator semantics — candidates confuse extend (adds columns) with summarize (aggregates rows), or pick search because it sounds like it finds patterns.

How to eliminate wrong answers

Option B is wrong because extend adds calculated columns to each row without grouping or aggregating, so it cannot identify patterns across multiple events. Option C is wrong because search performs a text search across tables and columns but does not aggregate results into counts or grouped patterns. Option D is wrong because project selects and renames columns, shaping output but not aggregating rows.

143
MCQeasy

You are hunting for privileged account abuse in Microsoft Entra ID. Which table in Microsoft Sentinel contains audit logs for changes to directory roles?

A.IdentityLogonEvents
B.AuditLogs
C.SigninLogs
D.DeviceLogonEvents
AnswerB

AuditLogs records Microsoft Entra ID directory activity, including role membership and role definition changes, so it directly satisfies the requirement to hunt privileged account abuse through directory role modifications. SigninLogs covers authentication events instead, not administrative role changes.

Why this answer

AuditLogs in Microsoft Sentinel contain audit data from Microsoft Entra ID, including changes to directory roles. Option A (IdentityLogonEvents) is incorrect as it contains identity protection events. Option C (SigninLogs) is incorrect because it contains user sign-in events.

Option D (DeviceLogonEvents) is incorrect as it logs device logon events.

144
Multi-Selecteasy

Which TWO techniques are commonly used in threat hunting to identify potential malicious activity? (Choose two.)

Select 2 answers
A.Searching for known indicators of compromise (IoCs).
B.Disabling security controls to observe attacker behavior.
C.Analyzing anomalies in baseline behavior.
D.Waiting for alerts from automated detection tools.
E.Automatically blocking all suspicious traffic.
AnswersA, C

Searching for known indicators of compromise lets hunters match observed artefacts — file hashes, IP addresses, domains — against threat intelligence. This reactive technique rapidly confirms whether known malicious infrastructure or payloads are present in the environment, satisfying one recognised threat hunting methodology.

Why this answer

Option A is correct because threat hunting commonly begins with searching for known indicators of compromise (IoCs) such as malicious IP addresses, file hashes, domain names, and registry keys, which can reveal evidence of past or ongoing attacks. Option C is correct because analyzing anomalies in baseline behavior—deviations from normal user, endpoint, or network activity—helps hunters uncover unknown or evasive threats that signature-based tools may miss. Disabling security controls (B) is not a threat-hunting technique; it weakens defenses and is unsafe.

Waiting for alerts from automated detection tools (D) is reactive monitoring rather than proactive hunting. Automatically blocking all suspicious traffic (E) is a prevention/response action, not an investigative hunting method.

Exam trap

The trap is selecting 'wait for alerts' or 'block traffic' — both are operational security activities, not threat hunting techniques, and distract from the proactive, investigative nature of hunting.

145
MCQeasy

A security analyst is reviewing a threat hunting query in Microsoft Sentinel that uses the Kusto Query Language (KQL) to identify potential lateral movement. The query returns a large number of false positives. What is the most effective way to reduce false positives while maintaining detection coverage?

A.Increase the threshold for the anomaly score in the query.
B.Add allowlist conditions to exclude known administrative tools.
C.Reduce the time range of the query to the last 1 hour.
D.Replace the query with a different data source that has less noise.
AnswerB

Allowlisting known administrative tools removes legitimate remote-management activity from the result set, cutting false positives without narrowing the query's scope. Detection coverage for genuine lateral movement persists, since only trusted binaries are excluded rather than whole event categories.

Why this answer

Adding allowlist conditions, such as excluding known administrative tools or approved remote management traffic, directly reduces false positives without removing the core logic. Option A is wrong because increasing the threshold may miss true positives. Option C is wrong because reducing the time range may miss true positives and does not address false positives.

Option D is wrong because changing the data source may reduce detection coverage and does not necessarily reduce false positives in the current query.

146
MCQeasy

During a threat hunting exercise, you need to pivot from a suspicious IP address to find all related alerts and incidents in Microsoft Sentinel. Which feature should you use?

A.Workbook
B.Incidents blade
C.Investigation graph
D.Playbook
AnswerC

The Investigation graph is Microsoft Sentinel's entity-centric exploration tool, modeling relationships between IPs, hosts, accounts, and alerts as a visual map. From a suspicious IP entity you can double-click or expand to immediately surface all connected alerts, related incidents, and adjacent entities, making it the correct pivot path for threat hunting. It leverages the entity schema and graph data to show both direct and indirect connections.

Why this answer

The investigation graph in Microsoft Sentinel allows visual pivoting and exploration of entities, making it the correct tool for pivoting from a suspicious IP to find related alerts and incidents. Option A (Workbooks) is incorrect because workbooks are for creating dashboards and reports. Option B (Incidents blade) is incorrect because it shows incidents but does not provide entity relationship visualization.

Option D (Playbook) is incorrect because playbooks automate responses, not pivot investigations.

147
MCQeasy

You are threat hunting for credential dumping activity. Which Windows event ID is commonly associated with the use of tools like Mimikatz?

A.4624 (Successful Logon)
B.4768 (Kerberos Authentication Ticket Request)
C.4688 (Process Creation)
D.4672 (Special Logon)
AnswerC

Event ID 4688 records process creation with command-line auditing enabled, capturing Mimikatz execution and its suspicious arguments. This contrasts with 4624 logons or 4672 privilege assignment, which show access but not the credential-dumping tool itself.

Why this answer

Windows Event ID 4688 (Process Creation) logs every new process spawned on the system, including the execution of tools like Mimikatz. When Mimikatz runs, it creates a process (e.g., mimikatz.exe), and the 4688 event captures the command line, parent process, and user context, which are critical for detecting credential dumping activity.

Exam trap

Microsoft often tests the misconception that credential dumping is tied to authentication events (like 4624 or 4768), but the key indicator is the process creation event (4688) that captures the execution of the dumping tool itself.

How to eliminate wrong answers

Option A is wrong because Event ID 4624 (Successful Logon) records authentication events, not the execution of a process like Mimikatz; credential dumping occurs after logon, not during it. Option B is wrong because Event ID 4768 (Kerberos Authentication Ticket Request) tracks TGT requests to a domain controller, which is unrelated to local credential dumping via Mimikatz. Option D is wrong because Event ID 4672 (Special Logon) logs when a user is granted special privileges (e.g., SeTcbPrivilege), but it does not directly indicate process creation or execution of a credential dumping tool.

148
MCQeasy

A threat hunter wants to use Microsoft Defender for Cloud Apps to hunt for suspicious OAuth app permissions. Which activity type should the analyst investigate?

A.Failed logon attempts
B.File download from SharePoint
C.Mailbox forwarding rule created
D.OAuth app granting permissions
AnswerD

OAuth app granting permissions directly records consent events, capturing the scopes granted to each application. This satisfies the hunter's requirement to identify suspicious OAuth permissions, as the activity log exposes the specific delegated or application permissions assigned, enabling detection of illicit access or over-privileged third-party apps.

Why this answer

Suspicious OAuth app permissions are directly indicated by the activity type 'OAuth app granting permissions'. Option A (Failed logon attempts) is incorrect because it relates to authentication failures, not OAuth permissions. Option B (File download from SharePoint) is incorrect because it concerns data access, not permission grants.

Option C (Mailbox forwarding rule created) is incorrect because it involves email rules, not OAuth authorizations.

149
MCQmedium

During a threat hunt in Microsoft Sentinel, you find a series of suspicious sign-ins to Microsoft Entra ID from an IP address known to be associated with a threat actor. Which entity should you pivot on to investigate further?

A.IP address
B.User account
C.Application
D.Device
AnswerA

The IP address is the shared entity linking every suspicious sign-in, letting you pivot to enumerate all related authentication events, affected accounts and associated alerts. Pivoting on the IP exposes the full scope of the threat actor's activity.

Why this answer

The IP address is the key entity that links all suspicious sign-ins and is the initial pivot point for investigation. Option A is correct because the IP address is the common element across the sign-ins. Options B, C, and D are incorrect: the user account, application, and device may be related but are not the primary pivot from the IP address.

150
MCQhard

You are a threat hunter at Northwind Traders. The organization uses Microsoft Defender for Identity (MDI) and Microsoft Sentinel. You suspect a golden ticket attack may have occurred in the domain. You need to create a hunting query in Microsoft Sentinel that leverages data from MDI to detect possible golden ticket usage. Which of the following queries or approaches is most appropriate?

A.Query DeviceProcessEvents for processes related to Kerberos
B.Query SecurityAlert where AlertName contains 'Golden Ticket' or 'Suspicious Kerberos'
C.Query CommonSecurityLog for unusual DNS queries related to Kerberos
D.Query IdentityLogonEvents for failed Kerberos authentication
AnswerB

Querying SecurityAlert for alert names containing 'Golden Ticket' or 'Suspicious Kerberos' is correct because Microsoft Defender for Identity, which is integrated into Microsoft 365 Defender and surfaces alerts in the SecurityAlert table, provides high-fidelity detections specifically for forged TGT activity. MDI signals such as anomalous ticket granting service requests, unusual TGT size, or encryption downgrade attacks are aggregated here, making it the direct, authoritative source for identifying golden ticket usage without needing to reconstruct indicators from raw logs.

Why this answer

Microsoft Defender for Identity (MDI) generates security alerts for suspicious Kerberos activity, including golden ticket attacks, which are surfaced in Microsoft Sentinel via the SecurityAlert table. Querying SecurityAlert for AlertName containing 'Golden Ticket' or 'Suspicious Kerberos' directly leverages MDI's built-in detections. This is the most appropriate approach because MDI already analyzes domain controller traffic and creates high-fidelity alerts.

Exam trap

The trap is assuming you need to query raw event tables like DeviceProcessEvents or IdentityLogonEvents; candidates may overlook that MDI already provides pre-built alerts in SecurityAlert, which is the intended data source for MDI detections.

How to eliminate wrong answers

Option A is wrong because DeviceProcessEvents contains process creation events from Defender for Endpoint, not MDI Kerberos alerts; it would not directly detect golden ticket usage. Option C is wrong because CommonSecurityLog typically ingests syslog from non-Microsoft sources like firewalls, not MDI alerts, and DNS queries are not the primary indicator of golden ticket attacks. Option D is wrong because IdentityLogonEvents contains logon events but failed Kerberos authentication is not indicative of a golden ticket, which often succeeds; golden tickets allow attackers to forge valid tickets, so failures are not the key signal.

← PreviousPage 2 of 3 · 178 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Perform threat hunting questions.