SC-200 Perform threat hunting Practice Question
Exhibit
Refer to the exhibit. ```kql let IPs = dynamic(['10.0.0.1', '10.0.0.2']); DeviceNetworkEvents | where Timestamp > ago(7d) | where RemoteIP in (IPs) | summarize count() by RemoteIP, DeviceName | where count_ > 5 ```
Refer to the exhibit. You are analyzing a potential C2 communication pattern. The KQL query returns no results despite known malicious IPs being active. What is the most likely cause?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The devices generating the events are not onboarded to Microsoft Defender for Endpoint.
If the devices generating the network events are not onboarded to Microsoft Defender for Endpoint, they will not produce any DeviceNetworkEvents, resulting in no query results even when malicious IPs are active. Option A is incorrect because the query does not need a Direction filter to return results; it may include both inbound and outbound by default. Option C is incorrect because filtering on ActionType is not necessary to see the connection events; the absence of a filter does not cause empty results. Option D is incorrect because RemoteIP is the correct field for the destination IP address in DeviceNetworkEvents; replacing it with DestinationIpAddress would not fix the missing data issue.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The query is missing a filter for Direction equal to 'Outbound'.
Why it's wrong here
DeviceNetworkEvents already records both inbound and outbound connections, and the exhibit's malicious IPs are external C2 endpoints, so outbound rows would match without a Direction filter. Adding Direction='Outbound' narrows results but does not cause the query to return nothing. Direction filtering is useful when isolating egress traffic specifically.
- ✓
The devices generating the events are not onboarded to Microsoft Defender for Endpoint.
Why this is correct
Microsoft Defender for Endpoint supplies the device telemetry that Sentinel's advanced hunting and C2-related tables query. Without onboarding, those devices emit no events, so the KQL query returns nothing despite the malicious IPs being active.
- ✗
The query does not include a filter for ActionType equal to 'ConnectionSuccess'.
Why it's wrong here
ActionType values in DeviceNetworkEvents include ConnectionSuccess, ConnectionFailed and ConnectionAttempted; filtering on ConnectionSuccess would exclude failed attempts but still return successful C2 connections, so it cannot produce zero rows. This filter is genuinely useful when hunting only established connections rather than all attempts.
- ✗
The RemoteIP field should be replaced with DestinationIpAddress.
Why it's wrong here
DeviceNetworkEvents does not expose a DestinationIpAddress column; the remote endpoint is held in RemoteIP, so renaming it would break the query entirely. The field name is already correct, so this cannot explain the empty result set. DestinationIpAddress appears in other tables, which makes the substitution tempting.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SC-200
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. An analyst runs this PowerShell script to query Microsoft Sentinel data. The query returns no results. What is the most likely reason?
medium- A.The timestamp filter is invalid; it should use TimeGenerated instead of Timestamp
- B.The query syntax is incorrect; summarize cannot be used after where
- ✓ C.No events matched the specific combination of process name and command line in the last 7 days
- D.The API endpoint URL is incorrect; it should be /v2/workspaces
Why C: The query syntax is valid (e.g., using where and summarize appropriately), the API endpoint and timestamp filter are standard for Microsoft Sentinel queries. The most probable reason for no results is that no events with rundll32.exe and javascript in the command line occurred within the specified 7-day window. Options A, B, and D describe issues that would typically cause errors, not just empty results, making C the most likely explanation.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.