SC-200 Perform threat hunting Practice Question
Which TWO of the following are key indicators of a potential DCSync attack that a threat hunter should look for in Microsoft Sentinel? (Select two.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Event ID 4662 with access mask for DS-Replication-Get-Changes
Option C is correct because DCSync abuse is detected through Windows Security Event ID 4662, which records access to Active Directory objects; the telltale sign is an access mask containing the DS-Replication-Get-Changes (and often DS-Replication-Get-Changes-All) control access right on the domain object, indicating replication data was requested. Option E is correct because legitimate directory replication is performed only by domain controllers, so replication requests (the same 4662/DS-Replication rights, or DRSUAPI replication traffic) originating from non-domain-controller accounts or workstations strongly indicate a DCSync attack using tools like Mimikatz or Impacket's secretsdump. Option A does not belong because failed logons from one IP indicate brute-force or password-spray activity, not replication abuse. Option B does not belong because creating a domain-admin account is a persistence or privilege-escalation action, not the replication-rights access pattern characteristic of DCSync. Option D does not belong because multiple Kerberos ticket requests suggest Kerberoasting or ticket harvesting, which is unrelated to the DS-Replication-Get-Changes access that defines DCSync.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Failed logon attempts from a single IP
Why it's wrong here
Failed logons from one IP indicate brute-force or password-spray activity, not DCSync, which abuses directory replication rights to harvest credential hashes. Brute-force detection is the right focus when hunting authentication-failure spikes, but DCSync shows as replication requests from non-domain-controller accounts.
- ✗
A new user account created with domain admin privileges
Why it's wrong here
Creating a privileged account is persistence or privilege escalation, not DCSync, which replicates credentials using Directory Replication Service permissions. Account-creation monitoring suits detecting rogue admin provisioning, whereas DCSync hunting targets replication traffic from unexpected principals.
- ✓
Event ID 4662 with access mask for DS-Replication-Get-Changes
Why this is correct
Event ID 4662 with the DS-Replication-Get-Changes access mask directly satisfies the stem's replication-permission indicator: DCSync abuses directory replication rights to harvest credential hashes. Monitoring this in Microsoft Sentinel detects non-domain-controller accounts requesting replication, the defining anomaly of DCSync activity.
- ✗
Multiple Kerberos ticket requests from a single user
Why it's wrong here
Bulk Kerberos ticket requests suggest Kerberoasting or ticket harvesting, not DCSync, which requests directory replication of credential data. Kerberos-request anomalies are the correct indicator when hunting service-account ticket abuse, but DCSync manifests through replication permissions being exercised.
- ✓
Directory replication requests from non-domain controller accounts
Why this is correct
DCSync abuses the directory replication service (DRSUAPI) by impersonating a domain controller. Legitimate replication originates only from DC machine accounts, so replication requests from non-DC accounts, especially user or workstation accounts, signal credential theft via secretsdump or Mimikatz.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.