Courseiva

CCNA Perform Threat Hunting Questions

28 of 178 questions · Page 3/3 · Perform Threat Hunting topic · Answers revealed

151
MCQmedium

You are investigating a series of failed logon attempts across multiple on-premises servers. You want to use Microsoft Sentinel to hunt for patterns of brute-force attacks. Which data source should you ingest to capture detailed authentication events from domain controllers?

A.Syslog from domain controllers
B.Windows Security Events via Windows Event Forwarding
C.Azure Activity Log
D.Microsoft 365 Defender events
AnswerB

Windows Security Events, collected via Windows Event Forwarding (WEF), are the authoritative source for on-premises failed-logon hunting because domain controllers log Event ID 4625 for every failed NTLM/Kerberos logon attempt. WEF uses HTTP/HTTPS (WinRM) and a collector-initiated subscription, preserving the full payload: source IP address, workstation name, logon type, and authentication package. This enables centralized correlation across all DCs in the domain and direct ingestion into a SIEM such as Sentinel.

Why this answer

Windows Security Events from domain controllers, collected via Windows Event Forwarding (WEF) or directly, include Event ID 4625 (failed logon) and other authentication events necessary for brute-force hunting. Option A is incorrect because Syslog from domain controllers does not capture Windows Security Events; Syslog is typically used for network devices or Linux systems. Option C is incorrect because Azure Activity Log records Azure resource management operations, not on-premises authentication events.

Option D is incorrect because Microsoft 365 Defender events cover cloud and endpoint alerts but not detailed authentication logs from on-premises domain controllers.

152
MCQeasy

A security team uses Microsoft Sentinel to hunt for signs of credential theft. They want to detect when a user account has been used to log in from an unusual location and then immediately performs a password reset for another user. Which hunting approach is most effective for this scenario?

A.Use a Microsoft Sentinel playbook to automatically flag any password reset
B.Write a KQL query that joins SigninLogs with AuditLogs on user principal name and times within a short window
C.Search the SigninLogs table for logins from unusual locations
D.Create a watchlist of known unusual locations and use it in a query against AuditLogs
AnswerB

Joining SigninLogs and AuditLogs on user principal name, constrained to a short time window, correlates an anomalous sign-in with a subsequent password reset. This temporal correlation across both tables surfaces the credential-theft sequence, which neither log alone reveals.

Why this answer

The most effective hunting approach is a KQL query that correlates SigninLogs (login events, including location) with AuditLogs (password reset operations) by joining on UserPrincipalName and filtering for events within a short time window. This detects the specific behavioral pattern: an unusual-location login immediately followed by a password reset for another user, which is a classic credential theft and privilege abuse indicator.

Exam trap

SC-200 often tests whether candidates understand that effective hunting requires correlating multiple log sources — the trap is selecting a single-table query or an automation that lacks the temporal and cross-table correlation needed to detect multi-step attack patterns.

How to eliminate wrong answers

Option A is wrong because a playbook that flags any password reset generates excessive false positives — password resets are routine, and the playbook lacks the correlation logic to identify the suspicious sequence. Option C is wrong because searching SigninLogs alone for unusual locations misses the second half of the attack pattern (the password reset) and cannot establish the temporal correlation. Option D is wrong because a watchlist of unusual locations used against AuditLogs alone ignores the sign-in context entirely — AuditLogs don't contain login location data, so the watchlist can't be applied meaningfully.

153
MCQhard

During a threat hunt, you discover a previously unknown malware variant that communicates over HTTPS to a command-and-control (C2) server. You want to create a custom detection in Microsoft Sentinel that triggers when any device in the organization resolves the C2 domain via DNS. Which data connector should you ensure is enabled?

A.DNS (Preview) via AMA
B.Azure Activity
C.Office 365 (Preview)
D.Windows Security Events via AMA
AnswerA

The DNS (Preview) via AMA connector ingests DNS query events from devices, which is the only telemetry that records domain resolution. Enabling it satisfies the requirement to trigger when any device resolves the C2 domain, since network connectors alone would not capture resolution.

Why this answer

The DNS (Preview) via AMA connector ingests DNS query logs from onboarded devices into Microsoft Sentinel, which is exactly the telemetry needed to detect when any device resolves the malicious C2 domain. Since the detection requirement is specifically about DNS resolution of the C2 domain, this connector provides the authoritative query events (including queried domain names and client IPs) that a custom analytics rule can match against. Without DNS logs flowing into the workspace, no KQL rule can trigger on domain resolution regardless of how well it is written.

Exam trap

SC-200 often tests whether candidates confuse endpoint security event telemetry with network-layer telemetry — the trap is picking 'Windows Security Events via AMA' because it sounds like it captures everything on the device, when in fact DNS query logs require the dedicated DNS connector.

How to eliminate wrong answers

Option B is wrong because Azure Activity only captures control-plane operations on Azure resources (e.g., role assignments, resource creation) and contains no DNS query telemetry. Option C is wrong because Office 365 (Preview) ingests audit and activity logs from Exchange, SharePoint, Teams, and similar workloads — it does not record endpoint DNS resolutions. Option D is wrong because Windows Security Events via AMA collects event log data such as logons, process creation, and object access, but not DNS client query events (those come from the DNS Client operational log, which is ingested by the DNS connector, not the Security Events connector).

154
MCQhard

During a threat hunt, you discover a suspicious PowerShell command that decoded a base64 string and executed a script. Which Microsoft Defender for Endpoint advanced hunting table should you query to find the decoded command line?

A.IdentityLogonEvents
B.DeviceProcessEvents
C.DeviceNetworkEvents
D.DeviceEvents
AnswerB

DeviceProcessEvents is the correct table because it captures process creation events on endpoints, and its ProcessCommandLine column stores the exact command line used to launch each process. This includes the PowerShell executable path, individual arguments, flags like -EncodedCommand or -ExecutionPolicy Bypass, and any obfuscated script text. The table also provides process ID, parent process, and initiating process command line, which are crucial for gaining full context on the suspicious PowerShell invocation during a threat hunt.

Why this answer

DeviceProcessEvents in Microsoft Defender for Endpoint advanced hunting contains process creation events, including the full command line used to launch processes. Since the suspicious PowerShell command executed a script, the decoded command line would be captured in this table under the ProcessCommandLine column.

Exam trap

SC-200 often tests the distinction between process-level telemetry (DeviceProcessEvents) and network or identity telemetry, causing candidates to choose DeviceEvents or DeviceNetworkEvents when the question asks for command-line details.

How to eliminate wrong answers

Option A is wrong because IdentityLogonEvents records authentication events (logon attempts, failures) and does not contain process command lines. Option C is wrong because DeviceNetworkEvents captures network connections and related metadata, not process execution details. Option D is wrong because DeviceEvents is a general table for various event types (e.g., file creation, registry changes) but does not specifically store process command lines — that is the domain of DeviceProcessEvents.

155
MCQmedium

During threat hunting, you identify a suspicious PowerShell process that executed encoded commands. Which Microsoft Defender XDR hunting capability would best help you trace the parent process and command-line arguments across the enterprise?

A.Automated investigation and response
B.Threat analytics
C.Device inventory
D.Advanced hunting
AnswerD

Advanced Hunting is the Microsoft 365 Defender tool purpose-built for proactively querying across deep time series and event tables via KQL, including DeviceProcessEvents, DeviceEvents, and associated network/file events. With schema-aware queries such as process parent-child joins, an analyst can pivot from a suspicious PowerShell process to its parent chain, command-line, file hashes, and related lateral-movement indicators. This makes it the correct surface for ad-hoc threat hunting and validating a specific suspicious process observed in the environment.

Why this answer

Advanced hunting in Microsoft Defender XDR uses KQL queries to trace parent processes and command-line arguments across devices, enabling detailed investigation of suspicious PowerShell activity. Option A is incorrect because automated investigation and response focuses on containment and remediation, not deep forensic tracing. Option B is incorrect because threat analytics provides threat intelligence and vulnerability information, not raw process event data.

Option C is incorrect because device inventory shows device configurations and status, but lacks process lineage and command-line details.

156
Multi-Selecteasy

Which TWO data sources in Microsoft Sentinel are commonly used for threat hunting related to lateral movement?

Select 2 answers
A.DeviceNetworkEvents
C.SecurityEvent
D.DnsEvents
E.AzureActivity
AnswersA, C

DeviceNetworkEvents, ingested via Microsoft Defender for Endpoint, records inbound and outbound connection attempts with initiating process and remote IP. This connection-level telemetry exposes the internal host-to-host traffic patterns that characterise lateral movement, satisfying the stem's threat-hunting requirement.

Why this answer

Options A and C are correct. DeviceNetworkEvents (Microsoft Defender for Endpoint) logs network connections, which can reveal lateral movement attempts between devices. SecurityEvent (Windows Event Logs) contains Event ID 4624 (logon) and 4688 (process creation), both critical for identifying lateral movement.

Option B (Syslog) is a general logging protocol not specific to lateral movement. Option D (DnsEvents) is more relevant to command and control or data exfiltration. Option E (AzureActivity) tracks Azure resource operations, not lateral movement within the environment.

157
MCQmedium

Your organization uses Microsoft Sentinel to monitor a hybrid environment consisting of on-premises servers and cloud workloads in Azure. As a threat hunter, you have been tasked with identifying potential lateral movement using pass-the-hash (PtH) attacks. You have enabled UEBA and connected Windows Event Logs, including Event ID 4624 (logon) and 4648 (explicit credentials). You need to create a hunting query that surfaces anomalous remote logons where the same account logon from a non-domain joined machine using NTLM authentication. Which KQL query should you use to start your hunt?

A.SecurityEvent | where EventID == 4624 and AccountType == 'User' and LogonType == 3 | where IpAddress != '' | summarize count() by Account, IpAddress
B.SecurityEvent | where EventID == 4624 and LogonType == 3 and LogonProcessName contains 'NTLM' | where TargetUserName !endswith '$' | where Computer !in (list of domain controllers) | project TimeGenerated, Account=TargetUserName, SourceWorkstation=WorkstationName, LogonProcessName
C.SecurityEvent | where EventID == 4624 and LogonType == 2 and LogonProcessName contains 'NTLM' | project TimeGenerated, Account=TargetUserName
D.SecurityEvent | where EventID == 4624 and LogonType == 10 and AuthenticationPackageName == 'NTLM' | project TimeGenerated, Account=TargetUserName, SourceIP=IpAddress
AnswerB

This query precisely identifies NTLM network logons by combining EventID 4624, LogonType 3, and LogonProcessName containing 'NTLM', which is the signature of pass-the-hash authentication. The `TargetUserName !endswith '$'` filter removes machine accounts, and the `Computer !in (list of domain controllers)` exclusion eliminates the large volume of legitimate DC-to-DC NTLM activity, leaving only suspicious user logons from non-DC hosts. By projecting TimeGenerated, Account, SourceWorkstation, and LogonProcessName, it retains the forensic context needed for incident investigation, making it the correct detection for PtH lateral movement.

Why this answer

Filters for logon type 3 (network), NTLM authentication (LogonProcessName contains NTLM), and non-domain joined workstations (WorkstationName not in list of domain controllers). Option A misses PtH indicators; Option C incorrectly uses RDP logon type 10; Option D focuses on interactive logons.

158
MCQeasy

During a threat hunt, you identify a user account that has been logging in from multiple geographic regions within a short time. Which Microsoft Defender for Cloud Apps feature should you use to investigate this anomaly?

A.Cloud Discovery
B.App permissions
C.File policy
D.Activity log
AnswerD

The activity log records every user action and sign-in event with source IP, location and timestamp, letting analysts correlate the impossible-travel sign-ins and trace subsequent suspicious activity. It directly satisfies the requirement to investigate an account authenticating from multiple geographic regions within a short window.

Why this answer

The Activity log in Microsoft Defender for Cloud Apps provides detailed records of user activities, including login locations and times, making it ideal for investigating anomalies like logins from multiple geographic regions. Option A (Cloud Discovery) is used to identify shadow IT and cloud app usage, not user login anomalies. Option B (App permissions) focuses on permissions granted to OAuth apps, not user activity.

Option C (File policy) is for monitoring and protecting files, not login events.

159
MCQmedium

Your organization uses Microsoft Defender for Endpoint and Microsoft Sentinel. As part of a threat hunting exercise, you need to detect potential lateral movement using remote desktop protocol (RDP). You want to identify devices that have initiated multiple RDP connections to different internal IP addresses within a short time frame. Which hunting query should you use in Microsoft Sentinel's Log Analytics workspace?

A.Syslog | where Facility == 'auth' and Message contains 'RDP' | summarize count() by HostName
B.DeviceProcessEvents | where ProcessCommandLine contains 'mstsc.exe' | summarize count() by DeviceName
C.DeviceNetworkEvents | where RemotePort == 3389 and ActionType == 'ConnectionSuccess' | summarize dcount(RemoteIP) by DeviceName
D.IdentityLogonEvents | where LogonType == 'RemoteInteractive' | summarize dcount(IPAddress) by DeviceName
AnswerC

DeviceNetworkEvents with RemotePort 3389 and ActionType 'ConnectionSuccess' captures successful RDP sessions, and summarising dcount(RemoteIP) by DeviceName surfaces devices connecting to many distinct internal addresses — exactly the fan-out pattern the stem's lateral movement hunt requires.

Why this answer

DeviceNetworkEvents is the Microsoft Defender for Endpoint table that records network connection telemetry, including the RemotePort and ActionType fields. Filtering on RemotePort == 3389 (the RDP port) with ActionType == 'ConnectionSuccess' and then using dcount(RemoteIP) by DeviceName surfaces devices that successfully connected to many distinct internal IPs — the classic signature of RDP-based lateral movement. This is the query pattern Microsoft recommends in Sentinel hunting workbooks for detecting RDP fan-out behavior.

Exam trap

SC-200 often tests whether candidates know which Defender for Endpoint advanced hunting table contains network connection metadata versus process or identity data — picking DeviceProcessEvents or IdentityLogonEvents instead of DeviceNetworkEvents is the classic mistake.

How to eliminate wrong answers

Option A is wrong because Syslog with Facility == 'auth' captures Linux authentication events, not Windows RDP connection telemetry, and it lacks the RemotePort/RemoteIP fields needed to count distinct destinations. Option B is wrong because DeviceProcessEvents only shows that mstsc.exe was launched locally — it cannot reveal the remote IPs contacted, so it cannot detect fan-out to multiple internal hosts. Option D is wrong because IdentityLogonEvents with LogonType == 'RemoteInteractive' records successful interactive logons but does not enumerate the network-level RDP connection attempts or the distinct RemoteIP targets needed to identify lateral movement patterns.

160
MCQmedium

During a threat hunt, you discover that a PowerShell script executed on multiple servers and established outbound connections to an external IP address. Which data source should you query in Microsoft Defender XDR to identify the specific command-line arguments used?

A.DeviceEvents
B.DeviceImageLoadEvents
C.DeviceProcessEvents
D.DeviceNetworkEvents
AnswerC

DeviceProcessEvents stores process creation telemetry, including the full command line and arguments for each executed process, so querying it reveals the exact PowerShell parameters used. Network connection tables record destination IPs but not the command-line arguments that launched the script.

Why this answer

DeviceProcessEvents in Microsoft Defender XDR contains detailed information about process creation, including the command-line arguments used when a process was started. Querying this table will reveal the specific arguments passed to the PowerShell script. This is the correct data source for command-line details.

Exam trap

The trap is confusing process events with network events. Candidates might pick DeviceNetworkEvents because the question mentions outbound connections, but the question asks for command-line arguments, which are in process events. DeviceEvents is a distractor because it's a general table.

How to eliminate wrong answers

Option A is wrong because DeviceEvents is a general table for various event types, but it does not specifically focus on process creation with command-line arguments; it may contain some process-related events but not as comprehensive as DeviceProcessEvents. Option B is wrong because DeviceImageLoadEvents records image (DLL) load events, not process command lines. Option D is wrong because DeviceNetworkEvents records network connections, which would show the outbound connections but not the command-line arguments of the process that initiated them.

161
MCQhard

Your organization uses Microsoft Defender XDR for threat hunting. You suspect a threat actor is using scheduled tasks for persistence. Which hunting query would you use in Microsoft 365 Defender advanced hunting to find newly created scheduled tasks?

A.DeviceEvents | where ActionType == 'ScheduledTaskCreated'
B.DeviceRegistryEvents | where RegistryKey contains 'Tasks'
C.DeviceProcessEvents | where FileName == 'schtasks.exe'
D.DeviceFileEvents | where FolderPath contains 'Tasks'
AnswerA

DeviceEvents records endpoint telemetry from Defender for Endpoint, and its ActionType field captures ScheduledTaskCreated when a new scheduled task is registered. Filtering on that value surfaces persistence activity directly, which is exactly what the hunting scenario requires.

Why this answer

Advanced hunting uses the DeviceEvents table to capture various security events, including scheduled task creation via the 'ScheduledTaskCreated' action type. Option A is correct because DeviceEvents with ActionType 'ScheduledTaskCreated' directly identifies newly created scheduled tasks. Option B (DeviceRegistryEvents) is incorrect because it captures registry modifications, and while scheduled tasks are stored in the registry, querying for 'Tasks' in the registry key is too broad and not specific to creation.

Option C (DeviceProcessEvents) is incorrect because 'schtasks.exe' is the command-line tool used to create scheduled tasks, but querying for process events would capture executions rather than the actual creation of tasks, and it may miss tasks created via other methods. Option D (DeviceFileEvents) is incorrect because it tracks file operations, and scheduled tasks are not typically represented as files in a folder; the 'Tasks' folder path might refer to the Windows Task Scheduler library, but file events for task files (like .job files) are not the primary way to detect creation.

162
Multi-Selecteasy

Which TWO data sources in Microsoft Sentinel are most valuable for hunting for command-and-control (C2) communications? (Choose two.)

Select 2 answers
A.Windows Event Logs (e.g., Security, System)
B.Azure Activity log
C.DNS logs (e.g., from DNS servers or Azure DNS Analytics)
D.Syslog from Linux servers
E.Network traffic logs (e.g., from firewalls or network security groups)
AnswersC, E

DNS logs, whether collected from internal DNS servers or via Azure DNS Analytics, are a top-tier C2 data source because malware frequently uses DNS to resolve the domain name of its command-and-control server. Every query name, client IP, and timestamp is captured, allowing defenders to correlate against threat intelligence feeds for known malicious domains or detect domain-generation-algorithm (DGA) patterns. This visibility into the resolution process is essential because C2 often leverages a legitimate-looking domain rather than a hard-coded IP address.

Why this answer

DNS logs (C) are highly valuable for C2 hunting because malware frequently uses DNS for domain generation algorithms (DGA), DNS tunneling, and resolving C2 domains, and Sentinel can ingest DNS server logs or Azure DNS Analytics to detect anomalous queries. Network traffic logs (E) from firewalls or NSGs are equally valuable because they reveal outbound connections to known malicious IPs, beaconing patterns, unusual ports, and data exfiltration flows that characterize C2 channels. Windows Event Logs (A) focus on host-level authentication, process, and service activity rather than the network communication patterns central to C2 detection.

Azure Activity log (B) records control-plane operations on Azure resources, not C2 traffic. Syslog from Linux servers (D) provides host and application events but does not directly expose the DNS or network connection metadata most useful for identifying C2.

Exam trap

SC-200 often tests whether candidates confuse control-plane logs (Azure Activity) with data-plane network telemetry — the trap is selecting Azure Activity log thinking it captures outbound traffic, when it only records resource management operations.

163
Multi-Selecteasy

Which TWO tables in Microsoft Defender XDR advanced hunting are most useful for detecting data exfiltration attempts? (Select two.)

Select 2 answers
A.DeviceProcessEvents
B.DeviceNetworkEvents
C.CloudAppEvents
D.EmailEvents
E.DeviceInfo
AnswersB, C

DeviceNetworkEvents records outbound connections with remote IP, port and initiating process, exposing transfers to unfamiliar destinations or large uploads. That network-layer visibility is what reveals exfiltration traffic leaving endpoints, complementing cloud-side logging rather than duplicating it.

Why this answer

DeviceNetworkEvents (B) is correct because it records outbound network connections from endpoints, including RemoteIP, RemotePort, RemoteUrl, and bytes sent/received, which lets you spot anomalous transfers to external or untrusted destinations indicative of exfiltration. CloudAppEvents (C) is correct because it captures activity in cloud applications and services (for example file downloads, sharing, and uploads via Microsoft 365 and other connected apps), which is where data is commonly staged and moved out. DeviceProcessEvents (A) shows process creation and command lines, which may reveal staging or archiving tools but not the actual data transfer, so it is less directly useful.

EmailEvents (D) covers mail flow and delivery metadata, which is relevant to phishing or email-based leaks but not general exfiltration channels. DeviceInfo (E) is only static asset and configuration inventory, so it contains no transfer activity to detect.

Exam trap

SC-200 often tests whether candidates can map a threat scenario to the correct telemetry table — the trap is choosing process or email tables because they are familiar, when exfiltration is best evidenced by network and cloud activity.

164
Multi-Selecteasy

Which TWO are common techniques used during threat hunting to identify suspicious behavior in Microsoft Defender XDR?

Select 2 answers
A.Updating antivirus signatures.
B.Searching for known indicators of compromise (IOCs).
C.Applying anomaly detection models to user behavior.
D.Configuring mail flow rules in Exchange Online.
E.Performing vulnerability scans on endpoints.
AnswersB, C

Matching known IOCs — file hashes, domains, IP addresses — against telemetry quickly flags artefacts already tied to confirmed campaigns. It is a core hunting technique because it converts threat intelligence into concrete queries across Defender XDR tables, surfacing compromised hosts without waiting for alerts.

Why this answer

Option B is correct because threat hunting in Microsoft Defender XDR commonly begins with searching for known indicators of compromise (IOCs) such as malicious file hashes, IP addresses, domains, or URLs using advanced hunting queries (KQL) against tables like DeviceNetworkEvents and DeviceFileEvents. Option C is correct because applying anomaly detection models to user behavior — for example, identifying unusual sign-in patterns or atypical activity via Microsoft Defender for Identity and Microsoft Sentinel UEBA — is a core proactive hunting technique for uncovering threats that signature-based detection misses. Option A is not a hunting technique; updating antivirus signatures is a routine preventive maintenance task performed by Defender Antivirus, not an investigative method.

Option D is incorrect because configuring mail flow rules in Exchange Online is an administrative mail-handling action, not a threat-hunting technique. Option E is incorrect because vulnerability scans identify unpatched weaknesses rather than actively hunting for suspicious or malicious behavior in Defender XDR telemetry.

Exam trap

The trap is confusing threat hunting with other security operations like vulnerability scanning or antivirus updates; candidates must recognize that threat hunting is proactive and intelligence-driven, not routine maintenance.

165
MCQeasy

Your team uses Microsoft Defender for Endpoint to hunt for signs of credential theft. You want to query for events where a process accesses the LSASS process memory. Which event type should you look for?

A.Process access (Event 4656)
B.Network connection (Event 5156)
C.Registry modification (Event 4657)
D.Process creation (Event 4688)
AnswerA

Process access events, recorded as Event 4656, capture when one process opens a handle to another with specific access rights. LSASS credential dumping appears here because tools request read access to lsass.exe memory, matching the hunting requirement.

Why this answer

Credential theft via LSASS memory access is captured by Windows Security Event ID 4656 (and its companion 4663), which logs handle requests to objects including processes. Defender for Endpoint surfaces this as 'Process access' events, making it the correct event type to query for LSASS access.

Exam trap

The trap is confusing process access (4656) with process creation (4688) — candidates often pick 4688 because they think 'process' is the key word, but the question asks about memory access, which is a handle/object access event.

How to eliminate wrong answers

Option B is wrong because Event 5156 logs Windows Filtering Platform network connections, which is unrelated to process memory access. Option C is wrong because Event 4657 logs registry value modifications, not process handle requests. Option D is wrong because Event 4688 logs process creation, which would show a tool like Mimikatz launching but not the actual LSASS memory access.

166
MCQmedium

You are a threat hunter in a Microsoft Sentinel workspace. You hypothesize that an attacker is using the legitimate tool PsExec to move laterally, but you want to detect it without relying on process names that are easily renamed. Which hunting approach using KQL best identifies PsExec-like lateral movement by examining named pipes?

A.Search DeviceNetworkEvents for connections to TCP port 445 where InitiatingProcessFileName is "psexec.exe".
B.Search SecurityEvent for EventID 4624 with LogonType 3 and a SubjectUserName ending with "$".
C.Search SecurityEvent for EventID 4688 where NewProcessName ends with "psexec.exe" or "psexesvc.exe".
D.Search SecurityEvent for EventID 5145 where ShareName contains "IPC$" and RelativeTargetName matches "*psexesvc*".
AnswerD

This is correct because PsExec creates a named pipe called 'psexesvc' on the target host when it executes. Event ID 5145 (A network share object was checked to see whether client can be granted desired access) with ShareName IPC$ and RelativeTargetName containing psexesvc is a reliable indicator of PsExec lateral movement. Hunting this named pipe artifact avoids dependence on the process name, which attackers can rename.

Why this answer

PsExec creates a named pipe called 'psexesvc' on the target system during execution. Hunting for Event ID 5145 with ShareName IPC$ and RelativeTargetName containing 'psexesvc' detects this behavior regardless of the source binary name, making it a reliable method for identifying lateral movement with PsExec-like tools. Other options either rely on easily changed process names or produce high false positives.

Exam trap

The trap here is focusing on process names like psexec.exe or psexesvc.exe, which attackers can rename, instead of the named pipe artifact that PsExec inherently creates.

167
MCQhard

The KQL query above is used in a threat hunt. What is the most likely scenario this query is designed to detect?

A.Identification of lateral movement using PsExec
B.Discovery of data exfiltration using FTP
C.Hunting for code execution via rundll32.exe loading JavaScript
D.Detection of regsvr32.exe being used to execute scriptlet files
AnswerC

This query is correctly hunting for a known LOLBin technique where an attacker uses rundll32.exe to execute JavaScript code by placing 'javascript:' in the command line. When PowerShell (or another process) launches rundll32 with that argument, it triggers the JScript engine to evaluate the supplied script, allowing arbitrary code execution while masquerading as a legitimate Windows binary. This pattern is documented in MITRE ATT&CK as Signed Binary Proxy Execution (T1218.011), and the combination of the parent-child process relationship and the 'javascript:' string makes it a strong hunting indicator.

Why this answer

The query specifically looks for rundll32.exe loading JavaScript files, which is a known technique for executing malicious code while evading detection. This aligns with option C, as it directly describes the behavior the query is designed to hunt for. The query likely includes process creation events where rundll32.exe is the parent or child process and the command line contains .js or .jse extensions, indicating JavaScript execution.

Exam trap

SC-200 often tests the ability to distinguish between different LOLBin techniques, such as confusing rundll32.exe with regsvr32.exe or misidentifying the specific script type being executed.

How to eliminate wrong answers

Option A is wrong because PsExec lateral movement typically involves the creation of services or named pipes, not rundll32.exe loading JavaScript files. Option B is wrong because FTP data exfiltration would involve network connections to FTP servers and file transfers, not rundll32.exe executing scripts. Option D is wrong because regsvr32.exe executing scriptlet files (e.g., .sct) is a different LOLBin technique; the query specifically targets rundll32.exe and JavaScript, not regsvr32.exe and scriptlets.

168
MCQmedium

Your threat hunt involves correlating alerts from Microsoft Defender for Cloud Apps with Microsoft Defender for Endpoint. Which Microsoft Sentinel integration should you use to unify these alerts for hunting?

A.Microsoft Sentinel's unified analytics rules and incident creation
B.Power Automate flows to merge alerts
C.Microsoft Graph API to pull alerts into a custom database
D.Azure Monitor Workbooks to display alerts side by side
AnswerA

Unified analytics rules in Microsoft Sentinel correlate alerts from multiple sources, including Microsoft Defender for Cloud Apps and Microsoft Defender for Endpoint, and group them into a single incident. This satisfies the requirement to unify cross-product alerts for hunting rather than viewing them separately.

Why this answer

Microsoft Sentinel provides built-in connectors and analytics rules to correlate alerts across Microsoft Defender XDR, including Defender for Cloud Apps and Defender for Endpoint. Option B (Power Automate) can automate workflows but does not provide a unified hunting experience or correlation. Option C (Microsoft Graph API) is programmatic and can retrieve alerts, but it is not a unified correlation tool.

Option D (Azure Monitor Workbooks) visualizes data but does not correlate or unify alerts for hunting.

169
Multi-Selecthard

Which TWO of the following are valid approaches to perform threat hunting using Microsoft Sentinel? (Choose two.)

Select 2 answers
A.Using Fusion analytics rule
B.Using the Hunting blade and Livestream
C.Using Automation rules to trigger playbooks
D.Using KQL queries in the Logs blade
E.Using Azure Policy to enforce compliance
AnswersB, D

The Hunting blade in Microsoft Sentinel provides a centralized interface containing built-in hunting queries mapped to MITRE ATT&CK techniques, allowing analysts to run predefined KQL searches and pivot on suspicious results. Livestream is a complementary feature that creates an ongoing KQL query session over live ingested data, presenting real-time results that update as logs flow in, with optional alerts on each result. This combination is a valid hunting approach because it directly supports proactive, iterative, and continuous investigation of workspace data.

Why this answer

The Hunting blade in Microsoft Sentinel provides a dedicated interface for proactive threat hunting, allowing analysts to run KQL queries and pivot through results. Livestream extends this by enabling continuous, real-time query execution against incoming data, which is essential for detecting patterns that evolve over minutes or hours. Both features are explicitly designed for iterative, hypothesis-driven threat hunting rather than automated detection.

Exam trap

The trap here is that candidates confuse automated detection rules (like Fusion) or response automation (like playbooks) with the manual, iterative process of threat hunting, which requires interactive querying and live monitoring rather than passive alerting.

170
MCQmedium

Your threat hunt identifies a process that is making outbound connections to an unknown IP address. Which Microsoft Defender for Endpoint action can you take to immediately isolate the device?

A.Isolate device
B.Collect investigation package
C.Block file
D.Run antivirus scan
AnswerA

Isolate device — Immediately disconnects the device from the network via Microsoft Defender for Endpoint's containment action, severing all inbound and outbound traffic while keeping the device powered on for forensic preservation. This is the correct first response to a process making outbound connections because it stops active data exfiltration and lateral movement without rebooting or losing volatile evidence, and it can be applied selectively if needed.

Why this answer

The 'Isolate device' action in Microsoft Defender for Endpoint immediately cuts off a device from all network communication except for the Defender for Endpoint service itself, preventing the malicious process from exfiltrating data or communicating with command-and-control servers. This is the only action that provides immediate network isolation while preserving the ability to remotely investigate and remediate the device. Other actions like collecting an investigation package or running an antivirus scan do not stop active outbound connections.

Exam trap

SC-200 often tests the distinction between actions that contain a threat (like isolation) versus those that only gather data or remediate files, so candidates must recognize that only 'Isolate device' immediately stops network communication.

How to eliminate wrong answers

Option B is wrong because 'Collect investigation package' gathers forensic data (running processes, network connections, etc.) but does not block network traffic, so the malicious process continues its outbound connections. Option C is wrong because 'Block file' prevents a specific file from executing on devices, but it does not isolate an already-running process or stop its network activity. Option D is wrong because 'Run antivirus scan' initiates a scan for malware but does not immediately sever network connections, allowing the threat to remain active during the scan.

171
MCQmedium

You are a threat hunter using Microsoft Sentinel. You have ingested syslog data from a Palo Alto firewall. You want to create a scheduled query rule that alerts when more than 10 outbound connections to a known bad IP address occur within 5 minutes. Which KQL function should you use to summarize the count?

A.project SourceIp, DestinationIp
B.extend Count = 1
C.summarize count() by SourceIp, DestinationIp
D.join kind=inner (Syslog)
AnswerC

`summarize count() by SourceIp, DestinationIp` aggregates events into per-source and per-destination groups, satisfying the stem's requirement to count outbound connections to a known bad IP. Grouping by DestinationIp lets you filter or threshold on that specific address, while the 5-minute window is applied by the scheduled query rule's frequency and lookback settings.

Why this answer

The `summarize` operator is the KQL aggregation function that groups rows by one or more columns and computes aggregate values such as `count()`, `sum()`, `avg()`, etc. In this scenario, `summarize count() by SourceIp, DestinationIp` produces a row per unique SourceIp/DestinationIp pair with the number of outbound connection events, which can then be filtered with a `where` clause (e.g., `where Count > 10`) to trigger the Sentinel scheduled query rule. This directly satisfies the requirement to count connections within the 5-minute rule window.

Exam trap

SC-200 often tests the difference between row-level operations (project, extend) and aggregation operations (summarize), so candidates may incorrectly choose extend or project when asked to count events.

How to eliminate wrong answers

Option A is wrong because `project` only selects or renames columns and does not perform any aggregation or counting. Option B is wrong because `extend Count = 1` merely adds a constant column with value 1 to every row; it does not group or sum events, so no meaningful count per source/destination is produced. Option D is wrong because `join kind=inner (Syslog)` is used to correlate two datasets on a matching key, not to aggregate or count events; it would not summarize connection counts.

172
MCQhard

You are a security operations analyst for Contoso Ltd. The company uses Microsoft Sentinel as its SIEM and Microsoft Defender for Cloud Apps for SaaS security. You are tasked with threat hunting for potential data exfiltration via Microsoft SharePoint Online. You need to create a hunting query that identifies users who have downloaded an unusually high number of files from SharePoint within a short time window compared to their historical baseline. The query should be run in Microsoft Sentinel using the OfficeActivity table. Which of the following approaches should you take?

A.Use the HuntingBookmark table to search for user activity
B.Query the CommonSecurityLog table for SharePoint events and look for high volumes of outbound traffic
C.Query the OfficeActivity table, filter for Operation=='FileDownloaded', summarize by UserId and bin(TimeGenerated, 1h), then use a join with a historical baseline table to detect deviations
D.Query the SecurityAlert table for alerts related to data exfiltration
AnswerC

Filtering OfficeActivity for Operation=='FileDownloaded' and summarising with bin(TimeGenerated, 1h) aggregates download counts per user per hour, satisfying the short-window requirement. Joining against a historical baseline table then surfaces deviations from each user's normal behaviour, which is precisely the anomaly detection the stem demands for SharePoint exfiltration hunting.

Why this answer

The OfficeActivity table in Microsoft Sentinel contains audit logs for Microsoft 365 services, including SharePoint Online. Filtering for Operation=='FileDownloaded' and summarizing by UserId and time bin allows you to count downloads per user per hour. Joining with a historical baseline table (e.g., created via a separate query or using the 'summarize' operator over a longer period) enables detection of anomalies compared to each user's normal behavior.

Exam trap

SC-200 often tests the correct table for a given data source; candidates may mistakenly choose CommonSecurityLog or SecurityAlert instead of OfficeActivity for SharePoint activity.

How to eliminate wrong answers

Option A is wrong because the HuntingBookmark table stores bookmarks created by analysts, not raw SharePoint activity events. Option B is wrong because CommonSecurityLog is for network security devices (e.g., firewalls, proxies), not SharePoint audit logs. Option D is wrong because SecurityAlert contains generated alerts, not raw activity data needed for proactive hunting.

173
MCQmedium

An analyst runs this PowerShell script to query Microsoft Sentinel data. The query returns no results. What is the most likely reason?

A.The timestamp filter is invalid; it should use TimeGenerated instead of Timestamp
B.The query syntax is incorrect; summarize cannot be used after where
C.No events matched the specific combination of process name and command line in the last 7 days
D.The API endpoint URL is incorrect; it should be /v2/workspaces
AnswerC

The script likely used a query such as DeviceProcessEvents | where ProcessCommandLine contains 'javascript:' combined with a filter for rundll32.exe as the process name. In most environments, rundll32.exe executing a JavaScript URI (e.g., JScript or VBScript) is an uncommon attack pattern that rarely occurs, so the query returned an empty table even though the syntax and endpoint are correct. The absence of matching records, not an API error or schema mistake, explains why no data was returned.

Why this answer

The query syntax is valid (e.g., using where and summarize appropriately), the API endpoint and timestamp filter are standard for Microsoft Sentinel queries. The most probable reason for no results is that no events with rundll32.exe and javascript in the command line occurred within the specified 7-day window. Options A, B, and D describe issues that would typically cause errors, not just empty results, making C the most likely explanation.

174
Multi-Selecthard

Which TWO actions are effective when threat hunting for lateral movement using remote desktop protocol (RDP) in Microsoft Defender XDR?

Select 2 answers
A.Query DeviceNetworkEvents for inbound connections on port 3389
B.Review CloudAppEvents for access to cloud apps from multiple IPs
C.Correlate RDP connections with successful logon events (Event ID 4624) with LogonType 10
D.Check for unusual email forwarding rules
E.Search for SMB file share connections
AnswersA, C

Querying DeviceNetworkEvents for inbound connections on TCP port 3389 is effective because this is the default port for Remote Desktop Protocol (RDP). Inbound RDP connections from unusual sources or to high-value hosts can indicate an attacker establishing a foothold or performing lateral movement. To refine the hunt, you would look for new or unexpected source IPs, repeated connection attempts, and combine these network observations with authentication logs.

Why this answer

Option A is correct because RDP uses TCP port 3389, so querying DeviceNetworkEvents for inbound connections on port 3389 in Microsoft Defender XDR surfaces potential RDP sessions initiated by an attacker moving laterally to a target device. Option C is correct because a successful RDP logon generates Windows Security Event ID 4624 with LogonType 10 (RemoteInteractive), so correlating those logon events with RDP network connections confirms actual interactive remote sessions rather than mere port scans or blocked attempts. Option B is not relevant because CloudAppEvents covers cloud application activity, not on-premises RDP lateral movement.

Option D is unrelated since unusual email forwarding rules indicate mailbox exfiltration or persistence, not RDP lateral movement. Option E is incorrect because SMB file share connections use ports 445/139 and represent a different lateral movement technique than RDP.

Exam trap

SC-200 often tests the distinction between network-level indicators (port 3389) and host-level logon types (LogonType 10 for RDP), and candidates may incorrectly select cloud app events or SMB connections as relevant to RDP lateral movement.

175
MCQmedium

During a threat hunt, you suspect a user may have exfiltrated data via email. Which Microsoft 365 Defender advanced hunting table should you query to review email attachments and their file hashes?

A.EmailUrlInfo
B.EmailAttachmentInfo
C.EmailEvents
D.EmailPostDeliveryEvents
AnswerB

EmailAttachmentInfo is the correct table because it is specifically designed to store metadata about files attached to emails, including the file name, file size, and crucially the SHA256 hash. In a threat hunt for data exfiltration, this hash lets you pivot to threat intelligence sources or correlate with command-and-control activities. This table is the only one among the options that directly provides a hash value to verify if a file was malicious or sensitive.

Why this answer

EmailAttachmentInfo is the correct table because it specifically contains metadata about email attachments, including the SHA256 hash of each attached file, file name, file type, and size. This table is designed for scenarios where you need to investigate suspicious attachments, such as during a data exfiltration hunt. The other tables focus on URLs, general email events, or post-delivery actions, not attachment details.

Exam trap

SC-200 often tests the distinction between email-related tables in advanced hunting, and candidates frequently confuse EmailAttachmentInfo with EmailEvents or EmailUrlInfo, forgetting that only EmailAttachmentInfo contains file hashes for attachments.

How to eliminate wrong answers

Option A is wrong because EmailUrlInfo stores information about URLs found in emails, such as the URL and its verdict, not attachments or file hashes. Option C is wrong because EmailEvents contains general email metadata like sender, recipient, subject, and delivery action, but does not include attachment hashes. Option D is wrong because EmailPostDeliveryEvents records post-delivery actions like ZAP (Zero-hour Auto Purge) or manual remediation, not attachment details.

176
MCQhard

You are threat hunting in Microsoft Sentinel using KQL. You want to identify potential beaconing activity by looking for regular, periodic network connections from a host. Which KQL operator or function is most appropriate to calculate the time intervals between connections and detect patterns?

A.serialize then use prev() and datetime_diff()
B.make-series count() on TimeGenerated step 1m
C.join kind=inner on RemoteIP
D.summarize count() by bin(TimeGenerated, 1m)
AnswerA

To detect beaconing, you need to calculate the time difference between consecutive connections from the same host. The serialize operator orders the rows, and prev() accesses the previous row's timestamp. datetime_diff() then computes the interval. By analyzing these intervals for regularity (e.g., low standard deviation), you can identify beaconing. This approach is flexible and works with irregular intervals, making it the most appropriate for this scenario.

Why this answer

Detecting beaconing requires analyzing the time intervals between consecutive network connections from a host. The serialize operator orders events, prev() retrieves the previous timestamp, and datetime_diff() calculates the interval. You can then summarize these intervals to find regularity, such as a low standard deviation or a common interval.

This method works even with jitter, making it the most effective for identifying command-and-control beaconing patterns.

Exam trap

The trap here is using aggregation functions like bin or make-series that group events into fixed windows, which can mask the precise intervals needed to detect beaconing with jitter.

177
MCQmedium

A security analyst is performing threat hunting in Microsoft Sentinel and wants to identify anomalous outbound network traffic from a compromised virtual machine. Which data source should be prioritized for this hunt?

A.Azure Activity Log
B.Azure Network Watcher flow logs
C.Windows Event Logs (Security, System)
D.Microsoft Entra ID sign-in logs
AnswerB

Azure Network Watcher flow logs are the correct source for this hunt because they record IP traffic through network security groups, capturing source/destination IPs, ports, protocols, and whether traffic was allowed or denied. These logs enable security analysts to identify anomalous outbound connections, such as a VM communicating with a known command-and-control (C2) IP on a non-standard port, by analyzing traffic patterns and byte/package counts. However, note that flow logs are aggregate and do not capture packet payloads, so they are best merged with other signals (e.g., threat intelligence) to confirm malicious intent.

Why this answer

Azure Network Watcher flow logs provide detailed information about IP traffic through Azure networks, making them ideal for detecting anomalous outbound traffic patterns. Option A (Azure Activity Log) focuses on control plane events, not network flows. Option C (Windows Event Logs) is for host-level events, not network traffic.

Option D (Azure AD sign-in logs) is for authentication events.

178
MCQhard

You run the KQL query above in Microsoft Sentinel. The query returns zero results even though you know some devices have connected to malicious IPs. What is the most likely cause?

A.The externaldata source URL is inaccessible from the Sentinel workspace.
B.The malicious IPs are not in the list.
C.The DeviceNetworkEvents table does not contain the RemoteIP column.
D.The let statement syntax is incorrect.
AnswerA

If the externaldata URL cannot be reached from the workspace, the query returns no rows because the external source yields nothing to join or filter. Connectivity to that URL is the prerequisite the query depends on.

Why this answer

The most likely cause is that the externaldata source URL is inaccessible from the Sentinel workspace. The externaldata operator in KQL retrieves data from an external storage location, such as an Azure Storage blob or a public URL. If the URL is unreachable due to network restrictions, authentication issues, or incorrect permissions, the query will return zero results even if the data exists.

This is a common pitfall when using externaldata in Microsoft Sentinel.

Exam trap

SC-200 often tests the externaldata operator's dependency on external source accessibility, and candidates may overlook network or permission issues, assuming the query logic is correct.

How to eliminate wrong answers

Option B is wrong because if the malicious IPs were not in the list, the query would still return results for other IPs, but the question states zero results, implying a complete failure to retrieve any data. Option C is wrong because the DeviceNetworkEvents table does include a RemoteIP column, so that is not the issue. Option D is wrong because the let statement syntax is correct; the problem is with the externaldata source accessibility, not the query syntax.

← PreviousPage 3 of 3 · 178 questions total

Ready to test yourself?

Try a timed practice session using only Perform Threat Hunting questions.