Courseiva
Perform threat hunting →mediumMultiple Choice

SC-200 Perform threat hunting Practice Question

You are a threat hunter in a Microsoft Sentinel workspace. You hypothesize that an attacker is using the legitimate tool PsExec to move laterally, but you want to detect it without relying on process names that are easily renamed. Which hunting approach using KQL best identifies PsExec-like lateral movement by examining named pipes?

⚠ Common exam trap

The trap here is focusing on process names like psexec.exe or psexesvc.exe, which attackers can rename, instead of the named pipe artifact that PsExec inherently creates.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Search SecurityEvent for EventID 5145 where ShareName contains "IPC$" and RelativeTargetName matches "*psexesvc*".

PsExec creates a named pipe called 'psexesvc' on the target system during execution. Hunting for Event ID 5145 with ShareName IPC$ and RelativeTargetName containing 'psexesvc' detects this behavior regardless of the source binary name, making it a reliable method for identifying lateral movement with PsExec-like tools. Other options either rely on easily changed process names or produce high false positives.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Search DeviceNetworkEvents for connections to TCP port 445 where InitiatingProcessFileName is "psexec.exe".

    Why it's wrong here

    This query only looks at network connections to SMB port 445 from a process named psexec.exe. It will miss renamed binaries and does not detect the actual named pipe creation on the target. Moreover, DeviceNetworkEvents may not capture the target-side named pipe activity. The named pipe approach is more robust because it detects the service creation behavior regardless of the source process name.

  • ✗

    Search SecurityEvent for EventID 4624 with LogonType 3 and a SubjectUserName ending with "$".

    Why it's wrong here

    Event ID 4624 with LogonType 3 indicates a network logon, which is common for many legitimate activities such as file shares and remote administration. Filtering on machine accounts ending with '$' will produce many false positives and does not specifically identify PsExec lateral movement. It lacks the specificity of the named pipe indicator, making it ineffective for a targeted hunt for PsExec-like behavior.

  • ✗

    Search SecurityEvent for EventID 4688 where NewProcessName ends with "psexec.exe" or "psexesvc.exe".

    Why it's wrong here

    This approach is flawed because it relies on the default process names. An attacker can easily rename psexec.exe to something innocuous, and psexesvc.exe may not be the actual binary name if the tool is modified. While Event ID 4688 with process creation is useful, filtering only on these names will miss renamed variants and does not leverage the named pipe artifact that is characteristic of PsExec behavior.

  • ✓

    Search SecurityEvent for EventID 5145 where ShareName contains "IPC$" and RelativeTargetName matches "*psexesvc*".

    Why this is correct

    This is correct because PsExec creates a named pipe called 'psexesvc' on the target host when it executes. Event ID 5145 (A network share object was checked to see whether client can be granted desired access) with ShareName IPC$ and RelativeTargetName containing psexesvc is a reliable indicator of PsExec lateral movement. Hunting this named pipe artifact avoids dependence on the process name, which attackers can rename.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.