Courseiva
Perform threat hunting →easyMultiple Select

SC-200 Perform threat hunting Practice Question

Which TWO data sources in Microsoft Sentinel are most valuable for hunting for command-and-control (C2) communications? (Choose two.)

⚠ Common exam trap

SC-200 often tests whether candidates confuse control-plane logs (Azure Activity) with data-plane network telemetry — the trap is selecting Azure Activity log thinking it captures outbound traffic, when it only records resource management operations.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

DNS logs (e.g., from DNS servers or Azure DNS Analytics)

DNS logs (C) are highly valuable for C2 hunting because malware frequently uses DNS for domain generation algorithms (DGA), DNS tunneling, and resolving C2 domains, and Sentinel can ingest DNS server logs or Azure DNS Analytics to detect anomalous queries. Network traffic logs (E) from firewalls or NSGs are equally valuable because they reveal outbound connections to known malicious IPs, beaconing patterns, unusual ports, and data exfiltration flows that characterize C2 channels. Windows Event Logs (A) focus on host-level authentication, process, and service activity rather than the network communication patterns central to C2 detection. Azure Activity log (B) records control-plane operations on Azure resources, not C2 traffic. Syslog from Linux servers (D) provides host and application events but does not directly expose the DNS or network connection metadata most useful for identifying C2.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Windows Event Logs (e.g., Security, System)

    Why it's wrong here

    Windows Event Logs (Security, System) capture authentication attempts, process creation, and system-level activity, but they lack the connection-level metadata and DNS query details needed to reliably spot command-and-control (C2) communication. While process injection or anomalous logons can be a secondary indicator of compromise, these logs do not directly show outbound network flows or domain-name resolutions to a known malicious C2 infrastructure.

  • ✗

    Azure Activity log

    Why it's wrong here

    Azure Activity log is a subscription-level audit trail for Azure Resource Manager control-plane operations, such as creating, updating, or deleting resources. It contains no network traffic data, DNS query information, or host-level process telemetry, so it cannot reveal C2 beaconing or outbound connections to an attacker-controlled server. At best, it might indicate a compromised identity, but it is not a primary source for C2 detection.

  • ✓

    DNS logs (e.g., from DNS servers or Azure DNS Analytics)

    Why this is correct

    DNS logs, whether collected from internal DNS servers or via Azure DNS Analytics, are a top-tier C2 data source because malware frequently uses DNS to resolve the domain name of its command-and-control server. Every query name, client IP, and timestamp is captured, allowing defenders to correlate against threat intelligence feeds for known malicious domains or detect domain-generation-algorithm (DGA) patterns. This visibility into the resolution process is essential because C2 often leverages a legitimate-looking domain rather than a hard-coded IP address.

  • ✗

    Syslog from Linux servers

    Why it's wrong here

    Syslog from Linux servers typically contains operating-system and application messages, SSH authentication events, and cron job output, but it does not inherently include network flow records or DNS query responses. Although some Linux services can log outbound HTTP or curl requests, standard syslog lacks the systematic, source-to-destination connection metadata and domain-name resolution data that C2 detection requires. Thus, it is far less valuable than dedicated DNS or network traffic logs for identifying command-and-control activity.

  • ✓

    Network traffic logs (e.g., from firewalls or network security groups)

    Why this is correct

    Network traffic logs from firewalls and Azure Network Security Groups (NSG) flow logs provide essential details on external connections, including source and destination IP addresses, ports, protocols, and timestamps. This metadata enables detection of C2 beaconing patterns, such as periodic outbound connections to a known malicious IP on a non-standard port, and is often enriched with threat-intelligence indicators. Unlike DNS logs, which focus on name resolution, network logs reveal the actual data paths being used, making them indispensable for identifying established C2 channels.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.