Courseiva
Perform threat hunting →easyMultiple Select

SC-200 Perform threat hunting Practice Question

Which TWO data sources in Microsoft Sentinel are commonly used for threat hunting related to lateral movement?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

DeviceNetworkEvents

Options A and C are correct. DeviceNetworkEvents (Microsoft Defender for Endpoint) logs network connections, which can reveal lateral movement attempts between devices. SecurityEvent (Windows Event Logs) contains Event ID 4624 (logon) and 4688 (process creation), both critical for identifying lateral movement. Option B (Syslog) is a general logging protocol not specific to lateral movement. Option D (DnsEvents) is more relevant to command and control or data exfiltration. Option E (AzureActivity) tracks Azure resource operations, not lateral movement within the environment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    DeviceNetworkEvents

    Why this is correct

    DeviceNetworkEvents, ingested via Microsoft Defender for Endpoint, records inbound and outbound connection attempts with initiating process and remote IP. This connection-level telemetry exposes the internal host-to-host traffic patterns that characterise lateral movement, satisfying the stem's threat-hunting requirement.

  • ✗

    Syslog

    Why it's wrong here

    Syslog carries Linux and appliance event streams, yet the lateral-movement sources in Sentinel are Windows security and endpoint telemetry. Syslog is the right choice when correlating Linux authentication failures, sudo usage or firewall events from non-Windows devices.

  • ✓

    SecurityEvent

    Why this is correct

    SecurityEvent captures Windows security auditing events, including logon types 3 and 10, explicit credential use, and privileged account activity. These authentication artefacts reveal remote access attempts between hosts, which is the defining signal of lateral movement that the stem asks you to hunt.

  • ✗

    DnsEvents

    Why it's wrong here

    DnsEvents records name-resolution queries, which can hint at internal reconnaissance, but lateral movement detection relies on authentication and process telemetry such as SecurityEvent and Sysmon. DNS logging is the right source when hunting domain-generation-algorithm activity or command-and-control beaconing.

  • ✗

    AzureActivity

    Why it's wrong here

    AzureActivity captures control-plane operations on Azure resources, not host-to-host authentication or remote execution, so it cannot evidence lateral movement across endpoints. It is the correct source for hunting suspicious role assignments, resource deletions or policy changes in the subscription.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.