SC-200 Perform threat hunting Practice Question
Which TWO data sources in Microsoft Sentinel are commonly used for threat hunting related to lateral movement?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DeviceNetworkEvents
Options A and C are correct. DeviceNetworkEvents (Microsoft Defender for Endpoint) logs network connections, which can reveal lateral movement attempts between devices. SecurityEvent (Windows Event Logs) contains Event ID 4624 (logon) and 4688 (process creation), both critical for identifying lateral movement. Option B (Syslog) is a general logging protocol not specific to lateral movement. Option D (DnsEvents) is more relevant to command and control or data exfiltration. Option E (AzureActivity) tracks Azure resource operations, not lateral movement within the environment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
DeviceNetworkEvents
Why this is correct
DeviceNetworkEvents, ingested via Microsoft Defender for Endpoint, records inbound and outbound connection attempts with initiating process and remote IP. This connection-level telemetry exposes the internal host-to-host traffic patterns that characterise lateral movement, satisfying the stem's threat-hunting requirement.
- ✗
Syslog
Why it's wrong here
Syslog carries Linux and appliance event streams, yet the lateral-movement sources in Sentinel are Windows security and endpoint telemetry. Syslog is the right choice when correlating Linux authentication failures, sudo usage or firewall events from non-Windows devices.
- ✓
SecurityEvent
Why this is correct
SecurityEvent captures Windows security auditing events, including logon types 3 and 10, explicit credential use, and privileged account activity. These authentication artefacts reveal remote access attempts between hosts, which is the defining signal of lateral movement that the stem asks you to hunt.
- ✗
DnsEvents
Why it's wrong here
DnsEvents records name-resolution queries, which can hint at internal reconnaissance, but lateral movement detection relies on authentication and process telemetry such as SecurityEvent and Sysmon. DNS logging is the right source when hunting domain-generation-algorithm activity or command-and-control beaconing.
- ✗
AzureActivity
Why it's wrong here
AzureActivity captures control-plane operations on Azure resources, not host-to-host authentication or remote execution, so it cannot evidence lateral movement across endpoints. It is the correct source for hunting suspicious role assignments, resource deletions or policy changes in the subscription.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.