Courseiva
Perform threat hunting →hardMultiple Select

SC-200 Perform threat hunting Practice Question

Which TWO of the following are key indicators of a potential DCSync attack that a threat hunter should look for in Microsoft Sentinel? (Select two.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Event ID 4662 with access mask for DS-Replication-Get-Changes

Option C is correct because DCSync abuse is detected through Windows Security Event ID 4662, which records access to Active Directory objects; the telltale sign is an access mask containing the DS-Replication-Get-Changes (and often DS-Replication-Get-Changes-All) control access right on the domain object, indicating replication data was requested. Option E is correct because legitimate directory replication is performed only by domain controllers, so replication requests (the same 4662/DS-Replication rights, or DRSUAPI replication traffic) originating from non-domain-controller accounts or workstations strongly indicate a DCSync attack using tools like Mimikatz or Impacket's secretsdump. Option A does not belong because failed logons from one IP indicate brute-force or password-spray activity, not replication abuse. Option B does not belong because creating a domain-admin account is a persistence or privilege-escalation action, not the replication-rights access pattern characteristic of DCSync. Option D does not belong because multiple Kerberos ticket requests suggest Kerberoasting or ticket harvesting, which is unrelated to the DS-Replication-Get-Changes access that defines DCSync.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Failed logon attempts from a single IP

    Why it's wrong here

    Failed logons from one IP indicate brute-force or password-spray activity, not DCSync, which abuses directory replication rights to harvest credential hashes. Brute-force detection is the right focus when hunting authentication-failure spikes, but DCSync shows as replication requests from non-domain-controller accounts.

  • ✗

    A new user account created with domain admin privileges

    Why it's wrong here

    Creating a privileged account is persistence or privilege escalation, not DCSync, which replicates credentials using Directory Replication Service permissions. Account-creation monitoring suits detecting rogue admin provisioning, whereas DCSync hunting targets replication traffic from unexpected principals.

  • ✓

    Event ID 4662 with access mask for DS-Replication-Get-Changes

    Why this is correct

    Event ID 4662 with the DS-Replication-Get-Changes access mask directly satisfies the stem's replication-permission indicator: DCSync abuses directory replication rights to harvest credential hashes. Monitoring this in Microsoft Sentinel detects non-domain-controller accounts requesting replication, the defining anomaly of DCSync activity.

  • ✗

    Multiple Kerberos ticket requests from a single user

    Why it's wrong here

    Bulk Kerberos ticket requests suggest Kerberoasting or ticket harvesting, not DCSync, which requests directory replication of credential data. Kerberos-request anomalies are the correct indicator when hunting service-account ticket abuse, but DCSync manifests through replication permissions being exercised.

  • ✓

    Directory replication requests from non-domain controller accounts

    Why this is correct

    DCSync abuses the directory replication service (DRSUAPI) by impersonating a domain controller. Legitimate replication originates only from DC machine accounts, so replication requests from non-DC accounts, especially user or workstation accounts, signal credential theft via secretsdump or Mimikatz.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.