Courseiva
Perform threat hunting →hardMultiple Select

SC-200 Perform threat hunting Practice Question

Which TWO actions are effective when threat hunting for lateral movement using remote desktop protocol (RDP) in Microsoft Defender XDR?

⚠ Common exam trap

SC-200 often tests the distinction between network-level indicators (port 3389) and host-level logon types (LogonType 10 for RDP), and candidates may incorrectly select cloud app events or SMB connections as relevant to RDP lateral movement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Query DeviceNetworkEvents for inbound connections on port 3389

Option A is correct because RDP uses TCP port 3389, so querying DeviceNetworkEvents for inbound connections on port 3389 in Microsoft Defender XDR surfaces potential RDP sessions initiated by an attacker moving laterally to a target device. Option C is correct because a successful RDP logon generates Windows Security Event ID 4624 with LogonType 10 (RemoteInteractive), so correlating those logon events with RDP network connections confirms actual interactive remote sessions rather than mere port scans or blocked attempts. Option B is not relevant because CloudAppEvents covers cloud application activity, not on-premises RDP lateral movement. Option D is unrelated since unusual email forwarding rules indicate mailbox exfiltration or persistence, not RDP lateral movement. Option E is incorrect because SMB file share connections use ports 445/139 and represent a different lateral movement technique than RDP.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Query DeviceNetworkEvents for inbound connections on port 3389

    Why this is correct

    Querying DeviceNetworkEvents for inbound connections on TCP port 3389 is effective because this is the default port for Remote Desktop Protocol (RDP). Inbound RDP connections from unusual sources or to high-value hosts can indicate an attacker establishing a foothold or performing lateral movement. To refine the hunt, you would look for new or unexpected source IPs, repeated connection attempts, and combine these network observations with authentication logs.

  • ✗

    Review CloudAppEvents for access to cloud apps from multiple IPs

    Why it's wrong here

    CloudAppEvents records activities in Microsoft cloud apps, such as sign-ins and file accesses, but does not capture endpoint-level network traffic like RDP connections. Multiple IP addresses seen in cloud app activity might suggest a compromised account, but it cannot confirm or refute RDP-based lateral movement to on-premises servers. Since the hunt is specifically about RDP lateral movement, this data source is not directly relevant.

  • ✓

    Correlate RDP connections with successful logon events (Event ID 4624) with LogonType 10

    Why this is correct

    Correlating incoming RDP connections with successful logon Event ID 4624 and LogonType 10 is a core technique because LogonType 10 indicates a remote interactive logon over RDP. By matching the timestamp and source IP of a network connection to port 3389 with a matching 4624 event, you can identify which RDP sessions actually authenticated successfully. This avoids false positives from connection attempts that never completed a logon.

  • ✗

    Check for unusual email forwarding rules

    Why it's wrong here

    Unusual email forwarding rules are a common indicator of data exfiltration or mailbox compromise, where an attacker redirects email to an external address. They do not indicate RDP-based lateral movement because they operate at the application layer within Exchange Online or on-premises mailboxes, not at the network layer of Windows endpoints. The question focuses on lateral movement via RDP, so this action is out of scope.

  • ✗

    Search for SMB file share connections

    Why it's wrong here

    Searching for SMB file share connections would target port 445, which is used for file sharing and can support lateral movement via tools like PsExec, but it is not the RDP protocol. RDP operates on port 3389 and involves different authentication mechanisms (LogonType 10) and network artifacts. While SMB activity can be part of a broader lateral movement hunt, it would not help identify RDP-specific attacks, making it ineffective for this specific question.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.