SC-200 Perform threat hunting Practice Question
In a threat hunt, you discover that a non-admin user account created a scheduled task that executes a PowerShell script to connect to an external IP on port 4444. Which of the following is the most likely interpretation of this activity?
⚠ Common exam trap
SC-200 often tests whether candidates can distinguish benign admin activity from attacker tradecraft — the trap is assuming 'scheduled task' or 'PowerShell' is inherently benign and missing the reverse-shell indicators (non-admin, external IP, port 4444).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The scheduled task is likely a reverse shell for persistence and remote access
A non-admin user creating a scheduled task that runs PowerShell to connect to an external IP on port 4444 is a textbook reverse shell pattern. Port 4444 is the default listener port for Metasploit's meterpreter payload, and scheduled tasks provide persistence across reboots. The combination of non-admin context, external IP, unusual port, and scheduled execution strongly indicates attacker persistence and command-and-control.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The user is performing legitimate remote administration
Why it's wrong here
Legitimate remote administration would typically leverage standard protocols such as RDP (TCP 3389), WinRM (TCP 5985/5986), or SSH (TCP 22), and it requires administrative privileges to configure or manage a host. A non-admin user executing a PowerShell script that opens an outbound connection to an external IP on port 4444 via a scheduled task does not match any sanctioned administrative workflow. The combination of an unusual high port and persistent scheduling strongly suggests an attacker's backdoor rather than routine remote management.
- ✗
The PowerShell script is a remote assistance tool
Why it's wrong here
Remote assistance tools such as Windows Remote Assistance or commercial support applications generally connect over well-known ports like TCP 3389 or use HTTPS (443) through a relay, and they are typically initiated interactively with the user's knowledge or via a support ticket. In this case, the PowerShell script is silently launched by a scheduled task to an arbitrary high port (4444), which is not an industry-standard remote-assistance port. This behavior is more consistent with a covert reverse shell designed to evade detection than a legitimate user-approved support session.
- ✗
The scheduled task is part of a software update mechanism
Why it's wrong here
Software update mechanisms communicate over predictable endpoints: Windows Update uses HTTP/HTTPS (80/443), WSUS can be configured on 8530/8531, and third-party updaters generally use HTTPS or vendor-specific registered ports. A scheduled task that runs a PowerShell script to connect to an external IP on port 4444 does not correspond to any known update service's traffic pattern or port usage. Furthermore, updates typically run as a privileged Windows service, not as a scheduled task under a non-admin user's context, making this explanation implausible.
- ✓
The scheduled task is likely a reverse shell for persistence and remote access
Why this is correct
A scheduled task that invokes PowerShell to establish an outbound connection to an external IP on port 4444 is a textbook reverse shell persistence mechanism. The attacker creates the scheduled task to execute at logon or on a recurring interval, ensuring reliable command-and-control access even after system reboots. PowerShell is frequently abused for this purpose because it enables 'living off the land' fileless attacks, often using System.Net.Sockets.TcpClient to send shell output without writing scripts to disk. Port 4444 is also a common default listener for Metasploit, and the non-admin context suggests the attacker is operating with limited privileges, possibly after phishing or lateral movement, maintaining access while working to elevate privileges.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.