Courseiva
Perform threat hunting →mediumMultiple Select

SC-200 Perform threat hunting Practice Question

Which TWO data sources are most relevant for threat hunting for lateral movement using remote service creation (e.g., WMI, PsExec)?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

DeviceNetworkEvents

Correct options: C and E. DeviceProcessEvents captures process creation on remote machines (e.g., services.exe, cmd.exe) which is indicative of remote service creation via WMI or PsExec. DeviceNetworkEvents captures outbound network connections to high ports (e.g., 135, 445) on remote machines. Option A (DeviceRegistryEvents) captures registry modifications, not directly relevant. Option B (DeviceEvents) is less specific for this scenario. Option D (DeviceFileEvents) captures file writes, not process execution.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    DeviceRegistryEvents

    Why it's wrong here

    DeviceRegistryEvents logs changes to the Windows registry, which often signal persistence mechanisms or configuration tampering. However, for threat hunting specifically focused on lateral movement, these events are secondary because they do not directly capture the network connections or process creation required to detect tools like PsExec. While an attacker may modify service keys to enable remote execution, this occurs after the movement, making registry telemetry less immediate and less specific for hunting active lateral movement.

  • ✗

    DeviceEvents

    Why it's wrong here

    DeviceEvents is a broad catch-all table that includes many unrelated system events such as driver loads, object access, and other internals, making it noisy and difficult to pinpoint attacks. Although it might occasionally contain a relevant telemetry item, it lacks the focused schema of dedicated tables like DeviceNetworkEvents or DeviceProcessEvents, which directly map to the MITRE ATT&CK techniques used for lateral movement. As a threat hunter, you would prefer the high-signal, purpose-built event types over this generic rollup.

  • ✓

    DeviceNetworkEvents

    Why this is correct

    DeviceNetworkEvents captures outbound and inbound connection attempts, including connections to TCP port 445, which is used for SMB file sharing to remote admin shares. Lateral movement techniques such as PsExec generate distinctive network connections to hosts on port 445 or any high-order port, making this telemetry among the most relevant for detecting an attacker pivoting across systems. The source IP, destination IP, and port data directly expose the network-level footprint of a move.

  • ✗

    DeviceFileEvents

    Why it's wrong here

    DeviceFileEvents logs file creation, modification, and file-related activities, but it does not record process creation or the command line associated with execution. While attackers often drop binaries or scripts that later run, the file event alone does not show the actual execution or the tool used, such as services.exe spawned by PsExec. For lateral movement, it is more effective to correlate file drops with process creation, so file events are less central on their own.

  • ✓

    DeviceProcessEvents

    Why this is correct

    DeviceProcessEvents contains rich process creation telemetry, including the process name, command line, parent process, and account, which is essential for spotting executions like services.exe started by PsExec. This table enables the hunter to see the exact binary and its arguments, revealing the execution of a tool widely used for lateral movement. The process tree gives the forensic chain necessary to validate a threat, making it one of the most relevant sources.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.