SC-200 Respond to security incidents Practice Question
Exhibit
{
"alert": {
"id": "alert-12345",
"title": "Suspicious PowerCLI execution on Exchange Server",
"severity": "High",
"entities": [
{
"type": "host",
"name": "EXCH01.contoso.com",
"ipAddress": "10.0.1.10"
},
{
"type": "user",
"name": "svc_exchange"
}
],
"evidence": [
{
"source": "Microsoft Defender for Identity",
"description": "PowerCLI executed remotely on Exchange server from IP 192.168.1.100"
}
]
}
}Refer to the exhibit. An alert in Microsoft Defender for Identity shows suspicious PowerCLI execution on an Exchange server. The service account 'svc_exchange' is used. What is the most likely true-positive scenario?
⚠ Common exam trap
It's easy for candidates to assume any PowerShell on an Exchange server is legitimate admin activity, but the exam specifically tests that PowerCLI is a VMware tool, not an Exchange management tool, making its execution on an Exchange server a clear red flag for compromise.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
An attacker using a compromised service account to access mailboxes via remote PowerShell
PowerCLI execution on an Exchange server, especially using a service account like 'svc_exchange', is a strong indicator of an attacker leveraging compromised credentials to remotely access Exchange via PowerShell. Microsoft Defender for Identity detects this because PowerCLI is not a native Exchange management tool; it is typically used by attackers to interact with Exchange Web Services (EWS) or Remote PowerShell (WinRM) for mailbox access, data exfiltration, or persistence. The combination of a service account (often over-privileged and not monitored) and PowerCLI from an unusual source or time makes this a true-positive compromise scenario.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
An attacker using a compromised service account to access mailboxes via remote PowerShell
Why this is correct
PowerCLI is a PowerShell-based module that an attacker can abuse to open a remote PowerShell session to Exchange's management and mailbox endpoints, despite being VMware's tooling. In this alert, the source is an internal service account that lacks the normal attributes of an approved admin account, and its remote PowerShell activity aligns with mailbox enumeration or data exfiltration via Exchange cmdlets. The use of PowerCLI as a launching point for these commands masks the attacker's intent while providing a shell for executing Get-Mailbox or Search-Mailbox queries.
- ✗
A security tool scanning for vulnerabilities
Why it's wrong here
Vulnerability scanners operate by probing network services for known weaknesses using protocols such as HTTP, SMB, LDAP, or RDP, and they do not invoke PowerCLI, which is a VMware-specific PowerShell module, to interact with Exchange. Their activity is typically unauthenticated or uses generic scanner credentials from a scanning appliance, not a compromised service account accessing mailboxes via remote PowerShell. The alert's specific pattern—a service account running Exchange remote PowerShell commands—does not match automated scanning behavior.
- ✗
A misconfigured backup application running from an external IP
Why it's wrong here
The alert's source IP is internal, which directly contradicts the premise of an external backup application. Even if a backup utility were misconfigured, it would rely on Exchange-aware mechanisms such as VSS or the Exchange Mailbox Replication Service backup APIs, not a PowerCLI-based remote PowerShell session to enumerate mailboxes. Backup activity also runs under a dedicated backup service account with clearly defined roles, whereas this alert describes a service account being used for PowerShell access to mailbox data, which is consistent with an attack, not a backup job.
- ✗
A legitimate IT admin running Exchange management scripts
Why it's wrong here
A legitimate Exchange administrator manages mailboxes through the Exchange Management Shell or the Exchange admin center, using natively supported Exchange cmdlets such as Get-Mailbox, not the VMware-oriented PowerCLI module. The account involved is a service account, not an interactive admin account, and its activity is being detected as remote PowerShell access to mailboxes—a method commonly used in account compromise and mailbox exfiltration. Standard administrative scripts would not require PowerCLI to reach Exchange, and they would not typically be flagged for accessing mailboxes through a non-standard remote PowerShell path.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.