Courseiva
Perform threat hunting →hardMultiple Select

SC-200 Perform threat hunting Practice Question

Which THREE of the following are indicators of a potential pass-the-hash attack that a threat hunter should investigate in Microsoft Defender for Identity?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Multiple failed logon attempts followed by a successful logon from the same IP

Option B is correct because a burst of failed logons immediately followed by a success from the same source IP is a classic credential-stuffing/brute-force precursor that often precedes or accompanies pass-the-hash, where stolen NTLM hashes are replayed to authenticate. Option C is correct because pass-the-hash relies on NTLM authentication, and anomalous NTLM traffic originating from a domain controller (which should normally use Kerberos for domain auth) is a strong Defender for Identity signal of hash replay or lateral movement. Option D is correct because LogonType 9 (NewCredentials) with Event ID 4624 indicates a process is using explicit alternate credentials via NTLM, which is exactly how tools like Mimikatz or PsExec execute pass-the-hash with a stolen hash rather than a password. Option A is not correct because a high volume of TGS requests points to Kerberoasting or ticket-based attacks, not pass-the-hash, which uses NTLM rather than TGS tickets. Option E is not correct because CPU spikes on domain controllers are a generic performance/availability indicator and are not a specific behavioral signature of pass-the-hash in Defender for Identity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    High volume of TGS requests from a single user

    Why it's wrong here

    TGS requests are more indicative of Kerberoasting.

  • ✓

    Multiple failed logon attempts followed by a successful logon from the same IP

    Why this is correct

    A burst of failed logons immediately followed by a success from the same IP signals credential brute-forcing or hash reuse, matching the pass-the-hash pattern where stolen NTLM hashes authenticate without knowing the plaintext password. Defender for Identity surfaces this sequence as suspicious authentication behaviour worth hunting.

  • ✓

    Anomalous NTLM authentication from a domain controller

    Why this is correct

    Pass-the-hash abuses NTLM authentication, so anomalous NTLM traffic originating from a domain controller indicates credential material being replayed from a host that should not initiate such logons. This deviation from normal NTLM baselines is a strong Defender for Identity hunting signal.

  • ✓

    Event ID 4624 with LogonType 9 (NewCredentials) from a non-privileged account

    Why this is correct

    LogonType 9 (NewCredentials) lets a process run under alternate credentials without a full interactive logon, which attackers abuse to inject stolen hashes. Its appearance from a non-privileged account is anomalous and directly matches the pass-the-hash technique in Defender for Identity.

  • ✗

    Anomalous spike in CPU usage on domain controllers

    Why it's wrong here

    CPU spike is not a direct indicator of pass-the-hash.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.