SC-200 Perform threat hunting Practice Question
Which TWO of the following are common techniques used by attackers to bypass security controls that a threat hunter should look for?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Process injection into trusted processes
Process injection into trusted processes (A) is a classic defense-evasion technique where an attacker writes malicious code into the memory space of a legitimate, trusted process (e.g., via CreateRemoteThread, APC injection, or process hollowing), allowing the payload to inherit the host process's privileges and blend into normal activity, which is exactly the kind of control bypass a threat hunter should detect. DLL sideloading (E) is another common evasion method in which a legitimate executable loads a malicious DLL from an attacker-controlled location due to insecure search-order or path resolution, hijacking trusted execution flow without triggering obvious alerts. By contrast, enabling multi-factor authentication (B), applying regular software updates (C), and enforcing strong password policies (D) are defensive hardening measures that strengthen security controls rather than techniques used to bypass them, so they are not attacker evasion methods.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Process injection into trusted processes
Why this is correct
Process injection writes malicious code into a trusted process's address space, so activity inherits that process's legitimacy and evades allow-listing and behavioural controls. Threat hunters detect it via anomalous memory allocation, thread creation or unexpected module loads.
- ✗
Enabling multi-factor authentication
Why it's wrong here
Multi-factor authentication is a defensive control that blocks credential-only access; attackers bypass controls, they do not enable them. It is tempting because MFA genuinely defeats password spraying, and it would be correct for a question asking which control mitigates stolen-credential sign-ins.
- ✗
Regular software updates
Why it's wrong here
Regular software updates are a defensive control that closes exploitable vulnerabilities; attackers bypass controls, they do not patch them. It is tempting because updates genuinely reduce attack surface, and it would be the correct answer to a question asking which practices harden systems against exploitation.
- ✗
Enforcing strong password policies
Why it's wrong here
Strong password policies are a preventive control that raises credential-guessing cost; attackers bypass controls rather than enforce them. It is tempting because password policy genuinely mitigates credential attacks, and it would be correct for a question asking which measures strengthen authentication against brute force.
- ✓
DLL sideloading
Why this is correct
DLL sideloading plants a malicious library beside a legitimate signed executable, which then loads it from its own directory. The trusted binary's signature satisfies application controls, so hunters must watch for unexpected DLLs in application folders.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.