Courseiva
Perform threat hunting →hardMultiple Select

SC-200 Perform threat hunting Practice Question

Which THREE techniques are effective for hunting for living-off-the-land (LotL) attacks using Microsoft Sentinel?

⚠ Common exam trap

SC-200 often tests the confusion between general security monitoring and specific LotL hunting techniques, leading candidates to select generic activities like software installation or logon type tracking.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Hunting for WMI activity using Event ID 5861 and correlating with process creation events.

Option B is correct because WMI is a native Windows administration mechanism frequently abused for LotL execution and persistence, and Event ID 5861 (WMI permanent event subscription creation in the WMI-Activity operational log) combined with process creation telemetry (e.g., Event ID 4688/Sysmon Event ID 1) exposes malicious subscription-based persistence and spawned processes. Option D is correct because PowerShell script block logging (Event ID 4104) captures de-obfuscated script content, making it effective for detecting encoded commands (-EncodedCommand), download cradles, and unusual parameters typical of LotL tradecraft. Option E is correct because correlating service installation (System log Event ID 7045) with subsequent network connections from administrative tools such as PsExec, sc.exe, or SMB/RPC traffic reveals lateral movement and remote execution that rely on built-in utilities. Option A does not belong because installing third-party software is not living-off-the-land activity, which by definition uses pre-installed, signed system binaries. Option C does not belong because Logon Type 5 is a service logon, and while service accounts can be abused, tracking non-interactive service logons alone is not a specific or effective LotL hunting technique compared with the correlated event-based methods above.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Monitoring for installation of third-party software on endpoints.

    Why it's wrong here

    Living-off-the-land attacks by definition use native Windows binaries and scripting tools, so monitoring for third-party software installation is irrelevant to detecting them and would miss the entire class of activity. Third-party installers are typically associated with traditional malware delivery, not with attackers who abuse built-in utilities to execute code without dropping a payload. Consequently, this control adds operational noise and does not contribute to hunting for LotL techniques like WMI abuse, service creation, or PowerShell encoding.

  • ✓

    Hunting for WMI activity using Event ID 5861 and correlating with process creation events.

    Why this is correct

    Event ID 5861 in the Microsoft-Windows-WMI-Activity/Operational log records the registration or modification of a permanent WMI event subscription, including the originating ProcessID and the consumer/filter details. Attackers commonly use WMI as a LotL lateral movement technique, so correlating this event with Windows process creation (Event ID 4688) reveals the exact command line, such as wmic.exe or PowerShell, that created the subscription. Without that correlation, 5861 can be mistaken for legitimate administrative tooling.

  • ✗

    Tracking non-interactive logon sessions (Logon Type 5).

    Why it's wrong here

    Logon Type 5 corresponds to a service starting via the Windows Service Control Manager and occurs constantly for normal operating system services and third-party software, producing voluminous, benign entries in the security log. It does not specifically indicate an attacker using built-in tools, because both legitimate services and those planted by tools like PsExec generate the same logon type. Simply tracking Type 5 without correlating it to service installation (Event ID 7045) or process lineage yields noise, not actionable LotL detections.

  • ✓

    Analyzing PowerShell script block logs (Event ID 4104) for encoded commands or unusual parameters.

    Why this is correct

    Event ID 4104, which logs PowerShell script block execution, is a rich telemetry source because attackers rely on encoded commands, obfuscation, and unusual parameters like -EncodedCommand, -WindowStyle Hidden, or -NoProfile to evade detection. Analyzing these entries for long Base64 strings or nonstandard parameter usage reveals malicious intent, and decoding the captured payload exposes the attacker's full command. Since PowerShell is a native Windows utility, this technique fits the LotL definition while still leaving a forensic footprint in the log.

  • ✓

    Correlating remote service creation events (Event ID 7045) with network connections from administrative tools.

    Why this is correct

    Event ID 7045 in the System log is generated every time a new service is installed, and attackers often use sc.exe, PsExec, or PowerShell to remotely create services as part of living-off-the-land lateral movement. When correlated with inbound network connections from administrative tools on ports such as 445 (SMB) or 135 (RPC), a service that appears immediately after a remote connection stands out from the normal service-installation baseline of patching or software deployment. This pairing exposes the remote origin and the built-in mechanism used to execute code.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.