Courseiva
Perform threat hunting →mediumMultiple Select

SC-200 Perform threat hunting Practice Question

Which THREE techniques are commonly used in Microsoft Sentinel threat hunting to identify command and control (C2) communication? (Select THREE.)

⚠ Common exam trap

SC-200 often tests whether candidates can distinguish C2 detection techniques (DNS tunneling, beaconing, TLS anomalies) from adjacent attack-stage techniques like phishing analysis or brute force detection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Detecting DNS tunneling

Detecting DNS tunneling (B) is correct because attackers frequently encode C2 data inside DNS queries and responses, and Sentinel hunting queries can flag anomalies such as high-entropy subdomains, excessive TXT/NULL record requests, or unusually long query names in DNS events. Analyzing network beaconing patterns (C) is correct because C2 implants typically check in at regular intervals, so hunting for periodic, low-volume outbound connections (for example, consistent time deltas or repeated small byte counts to the same destination) helps reveal compromised hosts. Examining SSL/TLS certificate anomalies (D) is correct because malicious C2 infrastructure often uses self-signed, expired, mismatched, or otherwise suspicious certificates, and Sentinel can correlate certificate metadata from network logs to identify such traffic. Analyzing email headers for phishing (A) is not a C2 communication technique; it targets initial access via email, and identifying brute force attempts (E) addresses credential attacks rather than command-and-control traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Analyzing email headers for phishing

    Why it's wrong here

    Email header analysis targets phishing delivery and sender spoofing, not the beaconing, DNS tunnelling or anomalous outbound connections that reveal C2 channels. It is tempting because Sentinel ingests email logs, but header inspection belongs to phishing investigations rather than C2 hunting.

  • ✓

    Detecting DNS tunneling

    Why this is correct

    Detecting DNS tunnelling is crucial for identifying C2 communication because attackers frequently encapsulate malicious traffic within legitimate DNS queries and responses. Microsoft Sentinel can analyse DNS logs, looking for anomalous patterns such as excessively long domain names, unusual query frequencies, or specific data encoding within DNS records. This technique effectively uncovers covert C2 channels, satisfying the requirement to identify command and control communication.

  • ✓

    Analyzing network beaconing patterns

    Why this is correct

    Command-and-control channels frequently use periodic, evenly spaced callbacks, so analysing network beaconing patterns exposes regular intervals and consistent payload sizes typical of implant check-ins. This satisfies the requirement to identify C2 communication through timing regularity rather than content inspection alone.

  • ✓

    Examining SSL/TLS certificate anomalies

    Why this is correct

    Self-signed, expired or mismatched certificates on outbound connections often betray malware C2 channels, since adversaries frequently reuse or poorly forge them. Inspecting certificate fields in Sentinel hunting queries surfaces beaconing traffic that domain or IP reputation alone would miss.

  • ✗

    Identifying brute force attempts

    Why it's wrong here

    Brute force detection examines repeated authentication failures against accounts or services, which indicates credential attacks, not the periodic outbound beaconing or domain patterns of C2 traffic. It is tempting because both appear in Sentinel hunting queries, but brute force maps to initial access rather than command and control.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.