SC-200 Perform threat hunting Practice Question
Which TWO data sources are commonly used in Microsoft Sentinel for threat hunting related to lateral movement? (Select TWO.)
⚠ Common exam trap
The trap is picking identity-centric tables like SigninLogs or AuditLogs because lateral movement sounds like an authentication issue — but the exam expects you to recognize that host-level (SecurityEvent) and network-level (DeviceNetworkEvents) telemetry is what actually reveals movement between machines.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SecurityEvent
SecurityEvent (B) is correct because it captures Windows Security event log data forwarded via AMA/Log Analytics, including logon events (4624, 4625), explicit credential use (4648), and special privilege assignment (4672) that are the primary telemetry for detecting lateral movement techniques like pass-the-hash and RDP pivoting. DeviceNetworkEvents (D) is correct because it comes from Microsoft Defender for Endpoint and records inbound/outbound network connections with process, IP, and port context, which is essential for spotting lateral movement such as SMB (445), WMI, PsExec, and remote service creation across hosts. SigninLogs (A) is not among the marked answers: it covers Entra ID authentication events and is more relevant to identity-based attacks and initial access than host-to-host lateral movement. OfficeActivity (C) tracks SharePoint, Exchange, and Teams user actions, which relate to data exfiltration or phishing rather than lateral movement across endpoints. AuditLogs (E) records Entra ID directory changes such as role assignments and app registrations, which support privilege escalation and persistence investigations, not lateral movement hunting.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
SigninLogs
Why it's wrong here
SigninLogs in Microsoft Sentinel captures Microsoft Entra ID authentication attempts to cloud apps, including the user, IP address, and application, but it lacks endpoint process, local logon, and network-level events. Lateral movement between on-premises hosts often uses SMB, WMI, or RDP and results in Windows Event 4624/4688 telemetry, not cloud sign-in records. These logs are better suited for detecting identity compromise or impossible travel, not the host-to-host propagation that defines lateral movement.
- ✓
SecurityEvent
Why this is correct
SecurityEvent is a primary data source for lateral movement because it ingests Windows security audit events from event log channels such as Security and Sysmon. Events like 4624 (successful logon, especially type 3 network logons), 4688 (process creation), and 4648 (explicit logon credentials) let analysts spot pass-the-hash, remote logon, and service creation by attackers. These host-level audit trails provide the ground truth needed to reconstruct a kill chain as an adversary moves between machines.
- ✗
OfficeActivity
Why it's wrong here
OfficeActivity (Microsoft 365 audit logs) track user operations in Exchange, SharePoint, Teams, and OneDrive, such as mailbox item access, file downloads, and external sharing. These logs may show the exfiltration phase or initial reconnaissance of sensitive documents, but they lack the endpoint process and network connection data necessary for detecting command execution, remote service creation, or SMB/RDP-based movement. As such, OfficeActivity is not a typical data source for lateral movement detection.
- ✓
DeviceNetworkEvents
Why this is correct
DeviceNetworkEvents, ingested from Microsoft Defender for Endpoint, records each network connection made by a process on an endpoint, with source/destination IPs, ports, protocol, and the owning process name. During lateral movement, attackers commonly connect to internal systems on ports such as 445 (SMB), 135/137 (RPC/NetBIOS), 5985/5986 (WinRM), or 3389 (RDP), which these logs expose. This network telemetry is essential for spotting internal propagation and should be joined with SecurityEvent logon events for robust detection.
- ✗
AuditLogs
Why it's wrong here
AuditLogs (Microsoft Entra ID audit logs) contain tenant-level directory changes such as user provisioning, group membership modifications, conditional access policy updates, and administrative role assignments. They do not include process creation, network connections, or local authentication events on endpoints, so they cannot directly reveal lateral movement between hosts. While directory changes might indicate a privilege escalation precursor, they are not a common data source specifically for detecting lateral movement.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.