Courseiva
Perform threat hunting →easyMultiple Select

SC-200 Perform threat hunting Practice Question

Which TWO of the following are common techniques used by attackers to bypass security controls that a threat hunter should look for?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Process injection into trusted processes

Process injection into trusted processes (A) is a classic defense-evasion technique where an attacker writes malicious code into the memory space of a legitimate, trusted process (e.g., via CreateRemoteThread, APC injection, or process hollowing), allowing the payload to inherit the host process's privileges and blend into normal activity, which is exactly the kind of control bypass a threat hunter should detect. DLL sideloading (E) is another common evasion method in which a legitimate executable loads a malicious DLL from an attacker-controlled location due to insecure search-order or path resolution, hijacking trusted execution flow without triggering obvious alerts. By contrast, enabling multi-factor authentication (B), applying regular software updates (C), and enforcing strong password policies (D) are defensive hardening measures that strengthen security controls rather than techniques used to bypass them, so they are not attacker evasion methods.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Process injection into trusted processes

    Why this is correct

    Process injection writes malicious code into a trusted process's address space, so activity inherits that process's legitimacy and evades allow-listing and behavioural controls. Threat hunters detect it via anomalous memory allocation, thread creation or unexpected module loads.

  • ✗

    Enabling multi-factor authentication

    Why it's wrong here

    Multi-factor authentication is a defensive control that blocks credential-only access; attackers bypass controls, they do not enable them. It is tempting because MFA genuinely defeats password spraying, and it would be correct for a question asking which control mitigates stolen-credential sign-ins.

  • ✗

    Regular software updates

    Why it's wrong here

    Regular software updates are a defensive control that closes exploitable vulnerabilities; attackers bypass controls, they do not patch them. It is tempting because updates genuinely reduce attack surface, and it would be the correct answer to a question asking which practices harden systems against exploitation.

  • ✗

    Enforcing strong password policies

    Why it's wrong here

    Strong password policies are a preventive control that raises credential-guessing cost; attackers bypass controls rather than enforce them. It is tempting because password policy genuinely mitigates credential attacks, and it would be correct for a question asking which measures strengthen authentication against brute force.

  • ✓

    DLL sideloading

    Why this is correct

    DLL sideloading plants a malicious library beside a legitimate signed executable, which then loads it from its own directory. The trusted binary's signature satisfies application controls, so hunters must watch for unexpected DLLs in application folders.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.