SC-200 Perform threat hunting Practice Question
You are a threat hunter at Northwind Traders. The organization uses Microsoft Defender for Identity (MDI) and Microsoft Sentinel. You suspect a golden ticket attack may have occurred in the domain. You need to create a hunting query in Microsoft Sentinel that leverages data from MDI to detect possible golden ticket usage. Which of the following queries or approaches is most appropriate?
⚠ Common exam trap
The trap is assuming you need to query raw event tables like DeviceProcessEvents or IdentityLogonEvents; candidates may overlook that MDI already provides pre-built alerts in SecurityAlert, which is the intended data source for MDI detections.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Query SecurityAlert where AlertName contains 'Golden Ticket' or 'Suspicious Kerberos'
Microsoft Defender for Identity (MDI) generates security alerts for suspicious Kerberos activity, including golden ticket attacks, which are surfaced in Microsoft Sentinel via the SecurityAlert table. Querying SecurityAlert for AlertName containing 'Golden Ticket' or 'Suspicious Kerberos' directly leverages MDI's built-in detections. This is the most appropriate approach because MDI already analyzes domain controller traffic and creates high-fidelity alerts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Query DeviceProcessEvents for processes related to Kerberos
Why it's wrong here
Querying DeviceProcessEvents for Kerberos-related processes such as mimikatz or klist is insufficient because a golden ticket attack does not necessarily execute a distinguishable process on endpoint machines; the core compromise occurs on the domain controller via forged TGTs, and MDI's detection relies on authentication and domain controller telemetry rather than process lineage. Process activity might reveal post-exploitation tools, but it misses the abuse of the Kerberos protocol itself and introduces high false positives from legitimate administrative tooling.
- ✓
Query SecurityAlert where AlertName contains 'Golden Ticket' or 'Suspicious Kerberos'
Why this is correct
Querying SecurityAlert for alert names containing 'Golden Ticket' or 'Suspicious Kerberos' is correct because Microsoft Defender for Identity, which is integrated into Microsoft 365 Defender and surfaces alerts in the SecurityAlert table, provides high-fidelity detections specifically for forged TGT activity. MDI signals such as anomalous ticket granting service requests, unusual TGT size, or encryption downgrade attacks are aggregated here, making it the direct, authoritative source for identifying golden ticket usage without needing to reconstruct indicators from raw logs.
- ✗
Query CommonSecurityLog for unusual DNS queries related to Kerberos
Why it's wrong here
Querying CommonSecurityLog for unusual DNS queries related to Kerberos is flawed because golden ticket abuse does not generate a characteristic DNS pattern; Kerberos authentication resolves host names normally, and the forged TGT is presented directly to the domain controller without requiring distinct DNS traffic. DNS queries would only show incidental resolution of service principal names, which is too noisy and indirect to distinguish a golden ticket attack from ordinary authentication, making this approach ineffective for threat hunting in this scenario.
- ✗
Query IdentityLogonEvents for failed Kerberos authentication
Why it's wrong here
Querying IdentityLogonEvents for failed Kerberos authentication is wrong because a golden ticket attack leverages a valid TGT that was forged with the KRBTGT account hash, so attempts do not produce authentication failures; the attacker appears as a legitimate principal and successfully obtains service tickets. Failed logons are more indicative of password guessing or Kerberoasting, not the use of a forged ticket, and thus this query would generate false negatives and overlook the attack entirely.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.