SC-200 Perform threat hunting Practice Question
Which TWO techniques are commonly used in threat hunting with Microsoft Sentinel to identify lateral movement? (Choose two.)
⚠ Common exam trap
SC-200 often tests whether candidates can distinguish lateral movement from adjacent phases — brute force (credential access) and mass deletion (impact) are common distractors that sound related but belong to different ATT&CK tactics.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Correlating service account usage with anomalous network connections.
Option D is correct because correlating service account usage with anomalous network connections surfaces lateral movement: attackers frequently reuse service accounts (often over SMB/RPC or WinRM) to pivot between hosts, and Microsoft Sentinel can join identity logs (SecurityEvent 4624 logon type 3/9, Microsoft Entra ID sign-in logs) with network telemetry (Syslog, CEF, or NSG flow logs) in KQL to flag a service account authenticating to hosts it never normally touches. Option E is correct because remote PowerShell execution across multiple machines is a classic lateral movement technique; Sentinel detects it via Event ID 4104 (PowerShell script block logging), 4688 process creation showing powershell.exe with -Command/-EncodedCommand, and WinRM operational logs (e.g., Microsoft-Windows-WinRM/Operational), especially when the same account spawns sessions on many hosts in a short window. Option A is not the best fit because port scanning is typically reconnaissance or discovery activity that precedes movement rather than lateral movement itself. Option B describes brute-force or password-spray credential access, which is an earlier attack phase, not lateral movement. Option C, mass file deletion, indicates impact or ransomware behavior rather than host-to-host pivoting.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Detecting port scanning activity from internal IPs.
Why it's wrong here
Port scanning is a network reconnaissance activity where an attacker probes internal hosts for open ports and services (MITRE ATT&CK T1046). This phase precedes lateral movement; the actual movement occurs when the attacker uses a discovered service to pivot to another system, so scanning alone does not constitute lateral movement.
- ✗
Searching for multiple failed logon attempts from a single IP.
Why it's wrong here
Multiple failed logon attempts from a single IP are characteristic of a brute-force or password-spraying attack (T1110), which seeks to crack credentials rather than spread through a network. Lateral movement typically relies on successfully authenticated, often single, logon events using stolen or valid credentials, not an abundance of failed authentication requests.
- ✗
Looking for mass file deletion events on file servers.
Why it's wrong here
Mass file deletion on file servers is a destructive action (T1485) commonly performed after data exfiltration or during ransomware cleanup to eliminate forensic evidence or cause business disruption. It does not involve an attacker establishing access from one host to another, which is the essence of lateral movement, and therefore it is not a lateral movement technique.
- ✓
Correlating service account usage with anomalous network connections.
Why this is correct
Service accounts often have elevated privileges and allow remote connections (e.g., SMB, WinRM, RDP) to multiple systems for legitimate application workloads. When an attacker compromises a service account, correlating its historical baseline with anomalous outbound network connections—such as connections to previously unseen hosts or non-standard protocols—can reveal lateral movement attempts that would otherwise blend in with normal service traffic.
- ✓
Identifying remote PowerShell execution across multiple machines.
Why this is correct
Remote PowerShell execution (e.g., via WinRM or PowerShell Remoting, T1021.006) enables an attacker to run commands on multiple remote hosts in rapid succession from a single pivot point. Monitoring for script block logs (Event ID 4104), remote session creation, or PowerShell spawning on many machines simultaneously provides direct evidence of lateral movement, as legitimate administration rarely exhibits such broad, coordinated execution.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.