SC-200 Perform threat hunting Practice Question
Which TWO of the following are effective techniques for identifying lateral movement in Microsoft Defender for Endpoint advanced hunting? (Choose two.)
⚠ Common exam trap
SC-200 often tests whether candidates can distinguish lateral movement from initial access and exfiltration — options about phishing or cloud uploads are distractors that describe other attack stages.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Search for remote desktop connections from non-administrative workstations
Option C is correct because in Microsoft Defender for Endpoint advanced hunting, RDP logons (e.g., LogonType 10 in DeviceLogonEvents) originating from non-administrative workstations are a classic lateral-movement indicator, since attackers pivot from a compromised user endpoint to other hosts rather than from trusted admin jump boxes. Option E is correct because NTLM authentication events (e.g., in DeviceLogonEvents or DeviceEvents with NTLM-related fields) can reveal pass-the-hash activity, where stolen NTLM hashes are reused to authenticate to remote systems without knowing the plaintext password, a hallmark of lateral movement. Option A is not the best fit because successful logons from public IP addresses typically indicate initial access or external exposure rather than internal lateral movement. Option B is unrelated because large uploads to cloud storage suggest exfiltration, not lateral movement. Option D is unrelated because phishing emails are an initial-access vector, not a lateral-movement detection technique in advanced hunting.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Check for successful logons from public IP addresses
Why it's wrong here
Successful logons from public IP addresses are a sign of external compromise or credential abuse rather than lateral movement, because they represent an attacker entering the network from the internet, not moving from one internal host to another. A genuinely lateral event will typically have an internal source IP and often involve re-used credentials. These logons could also originate from legitimate VPN endpoints or cloud egress ranges, making them indirect evidence at best.
- ✗
Look for large file uploads to cloud storage
Why it's wrong here
Large file uploads to cloud storage are more characteristic of data exfiltration, where attackers transfer stolen data out of the environment, than of lateral movement, which is the process of moving between hosts within the network to expand access. Exfiltration occurs after an attacker has already established a foothold and located valuable data, and it does not reveal the internal pivot path used to compromise additional systems. Therefore, monitoring this traffic is better suited to data loss prevention or exfiltration detection than to lateral movement hunting.
- ✓
Search for remote desktop connections from non-administrative workstations
Why this is correct
Unexpected remote desktop connections from non-administrative workstations are a strong lateral movement indicator because attackers frequently use RDP to hop to other systems once they compromise an endpoint. By searching for RDP sessions initiated from a standard user's workstation, a defender can spot activity that does not match the user's baseline behavior, especially when the destination is a server or privileged host. This technique corresponds to MITRE ATT&CK T1021.001, since legitimate users rarely initiate such connections from non-admin workstations.
- ✗
Monitor for phishing emails
Why it's wrong here
Monitoring for phishing emails focuses on the initial access stage, where attackers deliver a payload or trick a user into opening a malicious attachment, before any lateral movement has occurred. Phishing is a delivery mechanism for gaining a foothold, not a technique for spreading across hosts, so its detection does not directly uncover attacker movement between systems. Lateral movement detection should instead focus on authentication and remote access events that occur after the initial compromise.
- ✓
Analyze NTLM authentication events for pass-the-hash
Why this is correct
Analyzing NTLM authentication events for pass-the-hash is a valid lateral movement detection technique because attackers can use extracted password hashes to authenticate to remote systems without needing the plaintext password. In pass-the-hash, the NTLM hash is replayed as part of the authentication exchange, and anomalous patterns—such as a hash from a non-admin workstation being used on a server—can reveal this behavior. This maps to MITRE ATT&CK T1550.002 and is a critical hunting query in Windows environments where NTLM is still enabled.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.