Courseiva
Perform threat hunting →easyMultiple Select

SC-200 Perform threat hunting Practice Question

Which TWO data sources are commonly used in Microsoft Sentinel for threat hunting related to lateral movement? (Select TWO.)

⚠ Common exam trap

The trap is picking identity-centric tables like SigninLogs or AuditLogs because lateral movement sounds like an authentication issue — but the exam expects you to recognize that host-level (SecurityEvent) and network-level (DeviceNetworkEvents) telemetry is what actually reveals movement between machines.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SecurityEvent

SecurityEvent (B) is correct because it captures Windows Security event log data forwarded via AMA/Log Analytics, including logon events (4624, 4625), explicit credential use (4648), and special privilege assignment (4672) that are the primary telemetry for detecting lateral movement techniques like pass-the-hash and RDP pivoting. DeviceNetworkEvents (D) is correct because it comes from Microsoft Defender for Endpoint and records inbound/outbound network connections with process, IP, and port context, which is essential for spotting lateral movement such as SMB (445), WMI, PsExec, and remote service creation across hosts. SigninLogs (A) is not among the marked answers: it covers Entra ID authentication events and is more relevant to identity-based attacks and initial access than host-to-host lateral movement. OfficeActivity (C) tracks SharePoint, Exchange, and Teams user actions, which relate to data exfiltration or phishing rather than lateral movement across endpoints. AuditLogs (E) records Entra ID directory changes such as role assignments and app registrations, which support privilege escalation and persistence investigations, not lateral movement hunting.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    SigninLogs

    Why it's wrong here

    SigninLogs in Microsoft Sentinel captures Microsoft Entra ID authentication attempts to cloud apps, including the user, IP address, and application, but it lacks endpoint process, local logon, and network-level events. Lateral movement between on-premises hosts often uses SMB, WMI, or RDP and results in Windows Event 4624/4688 telemetry, not cloud sign-in records. These logs are better suited for detecting identity compromise or impossible travel, not the host-to-host propagation that defines lateral movement.

  • ✓

    SecurityEvent

    Why this is correct

    SecurityEvent is a primary data source for lateral movement because it ingests Windows security audit events from event log channels such as Security and Sysmon. Events like 4624 (successful logon, especially type 3 network logons), 4688 (process creation), and 4648 (explicit logon credentials) let analysts spot pass-the-hash, remote logon, and service creation by attackers. These host-level audit trails provide the ground truth needed to reconstruct a kill chain as an adversary moves between machines.

  • ✗

    OfficeActivity

    Why it's wrong here

    OfficeActivity (Microsoft 365 audit logs) track user operations in Exchange, SharePoint, Teams, and OneDrive, such as mailbox item access, file downloads, and external sharing. These logs may show the exfiltration phase or initial reconnaissance of sensitive documents, but they lack the endpoint process and network connection data necessary for detecting command execution, remote service creation, or SMB/RDP-based movement. As such, OfficeActivity is not a typical data source for lateral movement detection.

  • ✓

    DeviceNetworkEvents

    Why this is correct

    DeviceNetworkEvents, ingested from Microsoft Defender for Endpoint, records each network connection made by a process on an endpoint, with source/destination IPs, ports, protocol, and the owning process name. During lateral movement, attackers commonly connect to internal systems on ports such as 445 (SMB), 135/137 (RPC/NetBIOS), 5985/5986 (WinRM), or 3389 (RDP), which these logs expose. This network telemetry is essential for spotting internal propagation and should be joined with SecurityEvent logon events for robust detection.

  • ✗

    AuditLogs

    Why it's wrong here

    AuditLogs (Microsoft Entra ID audit logs) contain tenant-level directory changes such as user provisioning, group membership modifications, conditional access policy updates, and administrative role assignments. They do not include process creation, network connections, or local authentication events on endpoints, so they cannot directly reveal lateral movement between hosts. While directory changes might indicate a privilege escalation precursor, they are not a common data source specifically for detecting lateral movement.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.