SC-200 Perform threat hunting Practice Question
Which TWO data sources are essential for threat hunting in Microsoft Sentinel to detect lateral movement?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DeviceNetworkEvents (Microsoft Defender for Endpoint)
DeviceNetworkEvents (Microsoft Defender for Endpoint) provides network connections between devices, which can reveal lateral movement attempts. SecurityEvent (Windows Event Logs) provides security-related events such as remote logons (Event ID 4624) and service creation (Event ID 7045), which are key indicators of lateral movement. Option A (Microsoft Entra ID sign-in logs) focuses on cloud identity and is not directly relevant for on-premises lateral movement. Option D (CommonSecurityLog) typically comes from network perimeter devices and is not essential for internal lateral movement. Option E (DnsEvents) can provide insight into DNS queries but is less essential than the other two data sources for detecting lateral movement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Entra ID sign-in logs
Why it's wrong here
Microsoft Entra ID sign-in logs are auth-focused and capture cloud/identity-level events like successful or failed user logons, conditional access, and MFA. They help identify a compromised identity but lack host-level context such as the specific process, local privilege escalation, or network connection to another machine. Since lateral movement is an endpoint-to-endpoint activity that occurs after sign-in and often uses local accounts, these logs do not directly expose the internal connection chaining an attacker performs.
- ✓
DeviceNetworkEvents (Microsoft Defender for Endpoint)
Why this is correct
DeviceNetworkEvents is the workflow's core because it reveals each process's outbound and inbound network connections, including remote IP, remote port, protocol, and the initiating process image. Lateral movement requires a connection to another host via protocols like SMB (445), RDP (3389), or WinRM (5985), so hunting can simply look for unusual or repetitive connection patterns from a compromised host to internal addresses. This table also lets you join to process creation events, making it indispensable for reconstructing the full attack chain between systems.
- ✓
SecurityEvent (Windows Event Logs)
Why this is correct
SecurityEvent contains the Windows security audit trail: logon/logoff (4624/4635), process creation (4688), service creation (7045 is in Event table but SecurityEvent includes 4688 and 4624), and account management. Lateral movement leaves distinct footprints here, such as network logon type 3 from a different source IP, administrative session creation, or execution of remote tooling like PsExec and WMIC. These host-based events are the second essential source because they let you identify who/'which account moved, how authentication happened, and what was executed on the destination machine.
- ✗
CommonSecurityLog (Syslog)
Why it's wrong here
CommonSecurityLog is a generic receptacle for third-party syslog events from firewalls, proxies, and other network appliances. It does not natively define Windows event IDs, process names, or authentication details, and the log format varies by device, making correlation with host actions unreliable. For lateral movement, you need raw endpoint network and process telemetry, not a normalized container that is often noisy, incomplete, or without the specific fields needed to detect, say, a remote service creation or pass-the-hash. Thus it is supplementary infrastructure data, not an essential source.
- ✗
DnsEvents
Why it's wrong here
DnsEvents records DNS resolution attempts, including the queried domain, query type, and source client. While it can flag hosts reaching out to malicious domains, lateral movement usually uses IP addresses or NetBIOS names that were already resolved, so the DNS query itself is not directly implicated in the movement step. Additionally, DnsEvents lacks connection success/failure, remote port, and which process made the lookup, making it impossible to confirm that a connection actually occurred to a lateral target. It is useful for C2 detection, but not essential for lateral movement hunting.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.