SC-200 Perform threat hunting Practice Question
Which TWO actions are effective when threat hunting for lateral movement using remote desktop protocol (RDP) in Microsoft Defender XDR?
⚠ Common exam trap
SC-200 often tests the distinction between network-level indicators (port 3389) and host-level logon types (LogonType 10 for RDP), and candidates may incorrectly select cloud app events or SMB connections as relevant to RDP lateral movement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Query DeviceNetworkEvents for inbound connections on port 3389
Option A is correct because RDP uses TCP port 3389, so querying DeviceNetworkEvents for inbound connections on port 3389 in Microsoft Defender XDR surfaces potential RDP sessions initiated by an attacker moving laterally to a target device. Option C is correct because a successful RDP logon generates Windows Security Event ID 4624 with LogonType 10 (RemoteInteractive), so correlating those logon events with RDP network connections confirms actual interactive remote sessions rather than mere port scans or blocked attempts. Option B is not relevant because CloudAppEvents covers cloud application activity, not on-premises RDP lateral movement. Option D is unrelated since unusual email forwarding rules indicate mailbox exfiltration or persistence, not RDP lateral movement. Option E is incorrect because SMB file share connections use ports 445/139 and represent a different lateral movement technique than RDP.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Query DeviceNetworkEvents for inbound connections on port 3389
Why this is correct
Querying DeviceNetworkEvents for inbound connections on TCP port 3389 is effective because this is the default port for Remote Desktop Protocol (RDP). Inbound RDP connections from unusual sources or to high-value hosts can indicate an attacker establishing a foothold or performing lateral movement. To refine the hunt, you would look for new or unexpected source IPs, repeated connection attempts, and combine these network observations with authentication logs.
- ✗
Review CloudAppEvents for access to cloud apps from multiple IPs
Why it's wrong here
CloudAppEvents records activities in Microsoft cloud apps, such as sign-ins and file accesses, but does not capture endpoint-level network traffic like RDP connections. Multiple IP addresses seen in cloud app activity might suggest a compromised account, but it cannot confirm or refute RDP-based lateral movement to on-premises servers. Since the hunt is specifically about RDP lateral movement, this data source is not directly relevant.
- ✓
Correlate RDP connections with successful logon events (Event ID 4624) with LogonType 10
Why this is correct
Correlating incoming RDP connections with successful logon Event ID 4624 and LogonType 10 is a core technique because LogonType 10 indicates a remote interactive logon over RDP. By matching the timestamp and source IP of a network connection to port 3389 with a matching 4624 event, you can identify which RDP sessions actually authenticated successfully. This avoids false positives from connection attempts that never completed a logon.
- ✗
Check for unusual email forwarding rules
Why it's wrong here
Unusual email forwarding rules are a common indicator of data exfiltration or mailbox compromise, where an attacker redirects email to an external address. They do not indicate RDP-based lateral movement because they operate at the application layer within Exchange Online or on-premises mailboxes, not at the network layer of Windows endpoints. The question focuses on lateral movement via RDP, so this action is out of scope.
- ✗
Search for SMB file share connections
Why it's wrong here
Searching for SMB file share connections would target port 445, which is used for file sharing and can support lateral movement via tools like PsExec, but it is not the RDP protocol. RDP operates on port 3389 and involves different authentication mechanisms (LogonType 10) and network artifacts. While SMB activity can be part of a broader lateral movement hunt, it would not help identify RDP-specific attacks, making it ineffective for this specific question.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.