Courseiva
Perform threat hunting →mediumMultiple Select

SC-200 Perform threat hunting Practice Question

Which TWO of the following are effective techniques for identifying lateral movement in Microsoft Defender for Endpoint advanced hunting? (Choose two.)

⚠ Common exam trap

SC-200 often tests whether candidates can distinguish lateral movement from initial access and exfiltration — options about phishing or cloud uploads are distractors that describe other attack stages.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Search for remote desktop connections from non-administrative workstations

Option C is correct because in Microsoft Defender for Endpoint advanced hunting, RDP logons (e.g., LogonType 10 in DeviceLogonEvents) originating from non-administrative workstations are a classic lateral-movement indicator, since attackers pivot from a compromised user endpoint to other hosts rather than from trusted admin jump boxes. Option E is correct because NTLM authentication events (e.g., in DeviceLogonEvents or DeviceEvents with NTLM-related fields) can reveal pass-the-hash activity, where stolen NTLM hashes are reused to authenticate to remote systems without knowing the plaintext password, a hallmark of lateral movement. Option A is not the best fit because successful logons from public IP addresses typically indicate initial access or external exposure rather than internal lateral movement. Option B is unrelated because large uploads to cloud storage suggest exfiltration, not lateral movement. Option D is unrelated because phishing emails are an initial-access vector, not a lateral-movement detection technique in advanced hunting.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Check for successful logons from public IP addresses

    Why it's wrong here

    Successful logons from public IP addresses are a sign of external compromise or credential abuse rather than lateral movement, because they represent an attacker entering the network from the internet, not moving from one internal host to another. A genuinely lateral event will typically have an internal source IP and often involve re-used credentials. These logons could also originate from legitimate VPN endpoints or cloud egress ranges, making them indirect evidence at best.

  • ✗

    Look for large file uploads to cloud storage

    Why it's wrong here

    Large file uploads to cloud storage are more characteristic of data exfiltration, where attackers transfer stolen data out of the environment, than of lateral movement, which is the process of moving between hosts within the network to expand access. Exfiltration occurs after an attacker has already established a foothold and located valuable data, and it does not reveal the internal pivot path used to compromise additional systems. Therefore, monitoring this traffic is better suited to data loss prevention or exfiltration detection than to lateral movement hunting.

  • ✓

    Search for remote desktop connections from non-administrative workstations

    Why this is correct

    Unexpected remote desktop connections from non-administrative workstations are a strong lateral movement indicator because attackers frequently use RDP to hop to other systems once they compromise an endpoint. By searching for RDP sessions initiated from a standard user's workstation, a defender can spot activity that does not match the user's baseline behavior, especially when the destination is a server or privileged host. This technique corresponds to MITRE ATT&CK T1021.001, since legitimate users rarely initiate such connections from non-admin workstations.

  • ✗

    Monitor for phishing emails

    Why it's wrong here

    Monitoring for phishing emails focuses on the initial access stage, where attackers deliver a payload or trick a user into opening a malicious attachment, before any lateral movement has occurred. Phishing is a delivery mechanism for gaining a foothold, not a technique for spreading across hosts, so its detection does not directly uncover attacker movement between systems. Lateral movement detection should instead focus on authentication and remote access events that occur after the initial compromise.

  • ✓

    Analyze NTLM authentication events for pass-the-hash

    Why this is correct

    Analyzing NTLM authentication events for pass-the-hash is a valid lateral movement detection technique because attackers can use extracted password hashes to authenticate to remote systems without needing the plaintext password. In pass-the-hash, the NTLM hash is replayed as part of the authentication exchange, and anomalous patterns—such as a hash from a non-admin workstation being used on a server—can reveal this behavior. This maps to MITRE ATT&CK T1550.002 and is a critical hunting query in Windows environments where NTLM is still enabled.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.