Courseiva

SC-200 Respond to security incidents Practice Question

Which THREE data sources in Microsoft Sentinel can be used to detect lateral movement in a network? (Choose three.)

⚠ Common exam trap

The trap here is that candidates often select DNS logs (Option A) thinking they can detect lateral movement via unusual internal DNS queries, but DNS logs lack the authentication and process execution context required to confirm lateral movement, making them a supporting data source at best.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Defender for Endpoint (device events)

Microsoft Defender for Endpoint (MDE) provides detailed device-level events, including process creation, network connections, and logon sessions. These telemetry points are critical for detecting lateral movement because they reveal anomalous remote logins, service creation, or file execution on multiple endpoints, which are hallmarks of an attacker moving laterally.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    DNS logs

    Why it's wrong here

    DNS logs capture name resolution queries, showing which hosts requested which names, but they lack authentication and process context. While an attacker might query for a target hostname, DNS logs alone cannot distinguish a malicious connection from legitimate traffic, nor do they reveal whether access was successful. Therefore, they are insufficient for identifying lateral movement events like share access or remote logons.

  • ✓

    Microsoft Defender for Endpoint (device events)

    Why this is correct

    Microsoft Defender for Endpoint's device events provide deep host telemetry, including process creation, command lines, network connections, and local account logon events. This enables detection of lateral movement techniques such as PsExec, SMB/WMI remote execution, and RDP sessions at the endpoint level. Because it correlates specific processes with network activity and the originating host, it is a powerful source for hunting lateral movement in Sentinel.

  • ✓

    Windows Event Logs (Event ID 5140)

    Why this is correct

    Windows Event Log ID 5140 specifically records network share access, including the sharing machine, target path, and account used. Attackers often use administrative shares like ADMIN$ or C$ during lateral movement, and this event can reveal the source IP address. This log provides direct evidence that a remote account accessed a share, making it a key data source for detecting lateral movement.

  • ✓

    Windows Security Events (Event ID 4624)

    Why this is correct

    Windows Security Event ID 4624 is a successful logon event that captures details such as logon type, source workstation, and account name. Lateral movement often involves a compromised account logging on to multiple hosts via network or remote interactive logons, which appear as multiple 4624 events. By correlating these events across multiple systems in Sentinel, an analyst can spot an account hopping between machines, a classic sign of lateral movement.

  • ✗

    Microsoft Entra ID sign-in logs

    Why it's wrong here

    Microsoft Entra ID sign-in logs record authentication to cloud applications and Azure resources, not to on-premises Windows servers. Lateral movement typically involves network protocols such as SMB, RDP, or WinRM between internal hosts, which do not generate Entra ID sign-in events. Without host-based process and logon telemetry, these logs cannot confirm that a compromised account was used to move from one machine to another.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.